CVE-2026-71044

8.8

Oracle · Agile PLM

A vulnerability in the Export component of Oracle Agile PLM allows a low privileged attacker to achieve full system compromise via HTTP.

Executive summary

A high-severity vulnerability in the Oracle Agile PLM Export component enables low privileged attackers to seize control of the application.

Vulnerability

The vulnerability resides within the Export functionality, where a low privileged, network-authenticated attacker can exploit the system to gain unauthorized control.

Business impact

With a CVSS score of 8.8, this vulnerability poses a significant risk to the business, as an attacker gaining control of the Export component could potentially exfiltrate sensitive product data or manipulate export processes. This could lead to severe operational disruption and the loss of proprietary intellectual property.

Remediation

Immediate Action: Deploy the relevant Oracle security patches from the August 2026 release cycle to address the flaw in the Export component.

Proactive Monitoring: Monitor export activity logs for unexpected patterns or mass data extraction attempts that deviate from standard business workflows.

Compensating Controls: Utilize a Web Application Firewall to inspect traffic directed at the Export module and block requests containing suspicious payloads.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

Security teams must treat this vulnerability as a high priority due to the ease of exploitation. Patching the affected Oracle Agile PLM installation is the only definitive way to mitigate the risk of unauthorized system takeover.

More Oracle CVEs