CVE-2026-61166

Oracle · Agile PLM

A vulnerability in the User and User Group component of Oracle Agile PLM allows a low privileged, network-based attacker to gain unauthorized control of the application.

Executive summary

A high-severity vulnerability in Oracle Agile PLM allows authenticated attackers to compromise the system, potentially resulting in a full application takeover.

Vulnerability

This vulnerability allows a low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. The flaw resides in the User and User Group component and can lead to a full takeover of the platform.

Business impact

As Product Lifecycle Management (PLM) systems often contain highly sensitive intellectual property, the potential for unauthorized access is extreme. With a CVSS score of 8.8, this vulnerability represents a significant risk to the confidentiality and integrity of proprietary design and engineering data. A successful attack could result in the theft of trade secrets and severe operational disruption.

Remediation

Immediate Action: Apply the security updates provided in the July 2026 Oracle Critical Patch Update for version 9.3.6.

Proactive Monitoring: Audit user and group permission settings within the Agile PLM environment to detect any unauthorized modifications or privilege escalations.

Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall to monitor and block abnormal HTTP traffic to the PLM server.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Protecting intellectual property is paramount, and this vulnerability poses a direct threat to that objective. Security teams must ensure the July 2026 patch is applied to all instances of Agile PLM version 9.3.6 without delay.