{
  "cve": "CVE-2026-71042",
  "enrichment": {
    "affected": [
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "9.3.6"
            }
          }
        ],
        "enrichment": {
          "confidence": 95.0,
          "confidence_source": "inferred",
          "scores": [
            {
              "score": 95.0,
              "source": "inferred"
            },
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "original": {
          "product": "Oracle Agile PLM",
          "source": "cna",
          "vendor": "Oracle Corporation"
        },
        "product": "agile_plm",
        "vendor": "oracle"
      }
    ],
    "created": "2026-08-19T09:00:05.373602+00:00",
    "updated": "2026-08-20T19:45:03.898734+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$agile_plm"
    ],
    "weaknesses": [
      "CWE-284"
    ]
  },
  "epss": {
    "score": 0.0038
  },
  "mitre": {
    "cpes": [
      "cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*"
    ],
    "created": "2026-08-18T21:03:12.873000+00:00",
    "description": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: PGC / Excel Plugin).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 8.1,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/71xxx/CVE-2026-71042.json",
    "references": [
      "https://www.oracle.com/security-alerts/cspuaug2026.html"
    ],
    "title": null,
    "updated": "2026-08-19T16:05:29.380000+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$agile_plm"
    ],
    "weaknesses": []
  },
  "nvd": {
    "cpes": [
      "cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*"
    ],
    "created": "2026-08-18T21:18:03.990000+00:00",
    "description": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: PGC / Excel Plugin).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 8.1,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-71042.json",
    "references": [
      "https://www.oracle.com/security-alerts/cspuaug2026.html"
    ],
    "title": null,
    "updated": "2026-08-25T16:27:19.460000+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$agile_product_lifecycle_management"
    ],
    "weaknesses": [
      "CWE-284"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-08-18T21:15:00+00:00",
        "data": [
          {
            "details": {
              "new": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: PGC / Excel Plugin).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).",
              "old": null
            },
            "type": "description"
          },
          {
            "details": [
              "oracle",
              "oracle$PRODUCT$agile_plm"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "oracle",
                "oracle$PRODUCT$agile_plm"
              ],
              "removed": []
            },
            "type": "vendors"
          },
          {
            "details": {
              "added": [
                "https://www.oracle.com/security-alerts/cspuaug2026.html"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 8.1,
                  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "3c49c322-79dd-420e-ae68-44330a40e3d9"
      },
      {
        "created": "2026-08-19T09:15:00+00:00",
        "data": [
          {
            "details": {
              "new": "Unauthorized Data Modification and Denial of Service via Excel Plugin in Oracle Agile PLM 9.3.6",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-284"
              ],
              "removed": []
            },
            "type": "weaknesses"
          }
        ],
        "id": "99ca3a06-7a5b-483d-beba-0e92644ab2c6"
      },
      {
        "created": "2026-08-19T21:45:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Unauthorized Data Modification and Denial of Service via Excel Plugin in Oracle Agile PLM 9.3.6"
            },
            "type": "title"
          }
        ],
        "id": "17b9401e-50b7-406b-b548-944b62e4dd38"
      },
      {
        "created": "2026-08-20T02:30:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "no",
                    "Exploitation": "none",
                    "Technical Impact": "partial"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "a4d104de-9b9a-4be8-ba24-57ed1b352ba3"
      },
      {
        "created": "2026-08-20T08:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "Low‑Privileged HTTP Access Allows Unauthorized Data Modification and Denial of Service in Oracle Agile PLM",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "3a3b15c5-3c3f-4cb3-a379-106320fb42df"
      },
      {
        "created": "2026-08-20T20:00:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Low‑Privileged HTTP Access Allows Unauthorized Data Modification and Denial of Service in Oracle Agile PLM"
            },
            "type": "title"
          }
        ],
        "id": "ba5e2fc9-fe09-46b8-bc21-a8a8f9d81e4d"
      },
      {
        "created": "2026-08-25T16:45:00+00:00",
        "data": [
          {
            "details": [
              "oracle$PRODUCT$agile_product_lifecycle_management"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "oracle$PRODUCT$agile_product_lifecycle_management"
              ],
              "removed": []
            },
            "type": "vendors"
          }
        ],
        "id": "153dd215-97bf-45dd-8058-c24654faa776"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*",
        "cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "created": {
      "data": "2026-08-18T21:03:12.873000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: PGC / Excel Plugin).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 8.1,
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.0038
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "no",
            "Exploitation": "none",
            "Technical Impact": "partial"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://www.oracle.com/security-alerts/cspuaug2026.html"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": null,
      "provider": null
    },
    "updated": {
      "data": "2026-08-25T16:27:19.460000+00:00",
      "provider": "nvd"
    },
    "vendors": {
      "data": [
        "oracle",
        "oracle$PRODUCT$agile_plm",
        "oracle$PRODUCT$agile_product_lifecycle_management"
      ],
      "providers": [
        "mitre",
        "nvd",
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-284"
      ],
      "providers": [
        "nvd",
        "vulnrichment",
        "enrichment"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-08-18T21:03:12.873000+00:00",
    "description": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: PGC / Excel Plugin).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "no",
          "Exploitation": "none",
          "Technical Impact": "partial"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": null,
    "updated": "2026-08-19T15:42:42.938000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2026/71xxx/CVE-2026-71042.json",
    "weaknesses": [
      "CWE-284"
    ]
  }
}