CVE-2026-71067
8.8Oracle · Agile PLM MCAD Connector
An easily exploitable vulnerability in the Oracle Agile PLM MCAD Connector CAX Client allows a low privileged attacker to achieve full product takeover via HTTP.
Executive summary
A critical vulnerability in Oracle Agile PLM MCAD Connector allows a low privileged attacker to compromise the entire system.
Vulnerability
This vulnerability affects the CAX Client component of the Oracle Agile PLM MCAD Connector. It allows an attacker with low privileges and network access via HTTP to execute unauthorized actions, potentially leading to a complete takeover of the application.
Business impact
With a CVSS score of 8.8, this vulnerability poses a severe threat to business operations and data integrity. A successful exploit could allow an attacker to gain unauthorized control over the PLM environment, leading to the exfiltration of sensitive design data, intellectual property theft, or significant operational disruption.
Remediation
Immediate Action: Apply the security updates provided in the August 2026 Oracle Critical Security Patch Update immediately.
Proactive Monitoring: Review application access logs for suspicious HTTP requests originating from low-privileged user accounts.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to inspect and block anomalous HTTP traffic directed at the CAX Client component.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Organizations utilizing Oracle Agile PLM MCAD Connector version 3.6 must treat this vulnerability with high urgency. Applying the August 2026 security updates is the only definitive way to mitigate the risk of a full system takeover.