cve-2026-71043
HIGH CVSS 7.5 opencve
Description
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Timeline
- Published
- 2026-08-18 21:18 UTC
- Last Modified
- 2026-08-25
CVSS Details
CVSS details not available.
Affected Products
No product information available.
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
mitre | ||
| 3.1 | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
nvd | ||
| 3.1 | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
opencve |
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cve": "CVE-2026-71043",
"enrichment": {
"affected": [
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "semver",
"value": "9.3.6"
}
}
],
"enrichment": {
"confidence": 95.0,
"confidence_source": "inferred",
"scores": [
{
"score": 95.0,
"source": "inferred"
},
{
"score": 100.0,
"source": "matching"
}
]
},
"original": {
"product": "Oracle Agile PLM",
"source": "cna",
"vendor": "Oracle Corporation"
},
"product": "agile_plm",
"vendor": "oracle"
}
],
"created": "2026-08-19T08:00:04.597962+00:00",
"title": "Unauthenticated HTTP Access for Unauthorized Data Retrieval in Oracle Agile PLM 9.3.6",
"updated": "2026-08-20T23:15:05.207126+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$agile_plm"
]
},
"epss": {
"score": 0.00414
},
"mitre": {
"cpes": [
"cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*"
],
"created": "2026-08-18T21:03:13.200000+00:00",
"description": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 7.5,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2026/71xxx/CVE-2026-71043.json",
"references": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"title": null,
"updated": "2026-08-19T16:05:21.626000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$agile_plm"
],
"weaknesses": []
},
"nvd": {
"cpes": [
"cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*"
],
"created": "2026-08-18T21:18:04.110000+00:00",
"description": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 7.5,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2026/CVE-2026-71043.json",
"references": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"title": null,
"updated": "2026-08-25T16:27:17.497000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$agile_product_lifecycle_management"
],
"weaknesses": [
"CWE-284"
]
},
"opencve": {
"changes": [
{
"created": "2026-08-18T21:15:00+00:00",
"data": [
{
"details": {
"new": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"old": null
},
"type": "description"
},
{
"details": [
"oracle",
"oracle$PRODUCT$agile_plm"
],
"type": "first_time"
},
{
"details": {
"added": [
"cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"oracle",
"oracle$PRODUCT$agile_plm"
],
"removed": []
},
"type": "vendors"
},
{
"details": {
"added": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV3_1": {
"score": 7.5,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "bf31083b-17fa-46f7-b6fc-6067dcdff7aa"
},
{
"created": "2026-08-19T08:15:00+00:00",
"data": [
{
"details": {
"new": "Unauthenticated HTTP Access Leads to Unauthorized Data Exposure in Oracle Agile PLM 9.3.6",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-200",
"CWE-284"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "76556ad1-b92f-448e-81d5-1a27c95daf43"
},
{
"created": "2026-08-19T21:45:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Unauthenticated HTTP Access Leads to Unauthorized Data Exposure in Oracle Agile PLM 9.3.6"
},
"type": "title"
},
{
"details": {
"added": [],
"removed": [
"CWE-200"
]
},
"type": "weaknesses"
}
],
"id": "1c5e27f4-aee5-49e3-8413-206b165be5db"
},
{
"created": "2026-08-20T23:30:00+00:00",
"data": [
{
"details": {
"new": "Unauthenticated HTTP Access for Unauthorized Data Retrieval in Oracle Agile PLM 9.3.6",
"old": null
},
"type": "title"
}
],
"id": "12f5875a-9121-4394-8f2c-966ed2e1ece6"
},
{
"created": "2026-08-25T16:45:00+00:00",
"data": [
{
"details": [
"oracle$PRODUCT$agile_product_lifecycle_management"
],
"type": "first_time"
},
{
"details": {
"added": [
"cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"oracle$PRODUCT$agile_product_lifecycle_management"
],
"removed": []
},
"type": "vendors"
}
],
"id": "ad86ba62-a1b6-4f74-a685-8b2a082cba04"
}
],
"cpes": {
"data": [
"cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*"
],
"providers": [
"mitre",
"nvd"
]
},
"created": {
"data": "2026-08-18T21:03:13.200000+00:00",
"provider": "mitre"
},
"description": {
"data": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 7.5,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"provider": "mitre"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.00414
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {},
"provider": null
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": "Unauthenticated HTTP Access for Unauthorized Data Retrieval in Oracle Agile PLM 9.3.6",
"provider": "enrichment"
},
"updated": {
"data": "2026-08-25T16:27:17.497000+00:00",
"provider": "nvd"
},
"vendors": {
"data": [
"oracle",
"oracle$PRODUCT$agile_plm",
"oracle$PRODUCT$agile_product_lifecycle_management"
],
"providers": [
"mitre",
"nvd",
"enrichment"
]
},
"weaknesses": {
"data": [
"CWE-284"
],
"providers": [
"nvd"
]
}
}
}
Enrichment data
Aggregated bundle (all enrichments)