CVE-2026-61166
Oracle · Agile PLM
A vulnerability in the User and User Group component of Oracle Agile PLM allows a low privileged, network-based attacker to gain unauthorized control of the application.
Executive summary
A high-severity vulnerability in Oracle Agile PLM allows authenticated attackers to compromise the system, potentially resulting in a full application takeover.
Vulnerability
This vulnerability allows a low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. The flaw resides in the User and User Group component and can lead to a full takeover of the platform.
Business impact
As Product Lifecycle Management (PLM) systems often contain highly sensitive intellectual property, the potential for unauthorized access is extreme. With a CVSS score of 8.8, this vulnerability represents a significant risk to the confidentiality and integrity of proprietary design and engineering data. A successful attack could result in the theft of trade secrets and severe operational disruption.
Remediation
Immediate Action: Apply the security updates provided in the July 2026 Oracle Critical Patch Update for version 9.3.6.
Proactive Monitoring: Audit user and group permission settings within the Agile PLM environment to detect any unauthorized modifications or privilege escalations.
Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall to monitor and block abnormal HTTP traffic to the PLM server.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Protecting intellectual property is paramount, and this vulnerability poses a direct threat to that objective. Security teams must ensure the July 2026 patch is applied to all instances of Agile PLM version 9.3.6 without delay.