CVE-2026-21940

7.5

Oracle · Agile PLM

An unauthenticated vulnerability in the Oracle Agile PLM User and User Group component allows network-based attackers to compromise sensitive data.

Executive summary

An unauthenticated, easily exploitable vulnerability in Oracle Agile PLM version 9.3.6 allows attackers to gain unauthorized access to critical data.

Vulnerability

The vulnerability resides within the User and User Group component of Oracle Agile PLM. It allows an unauthenticated attacker with network access via HTTP to compromise the application and access sensitive system data.

Business impact

The vulnerability carries a CVSS 3.1 base score of 7.5, reflecting its high potential for unauthorized data disclosure. Successful exploitation could lead to the exposure of proprietary intellectual property, customer records, or supply chain data managed within the PLM environment, resulting in significant reputational damage and potential regulatory non-compliance.

Remediation

Immediate Action: Review the official Oracle Critical Patch Update advisory for January 2026 to identify and apply the necessary security patches for version 9.3.6.

Proactive Monitoring: Monitor application and server access logs for anomalous HTTP requests targeting the User and User Group management modules, particularly those originating from unknown or unauthorized network segments.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized access attempts or suspicious traffic patterns directed at the Agile PLM web interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high severity and the unauthenticated nature of this flaw, organizations running Oracle Agile PLM 9.3.6 must prioritize this update. Administrators should consult the January 2026 Oracle security bulletin immediately to verify if a patch is available and apply it to prevent unauthorized data exfiltration.

More Oracle CVEs

Sources