cve-2026-87266
HIGH CVSS 8.2 opencveVulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).
- Published
- 2026-09-15 20:19 UTC
- Last Modified
- 2026-09-22
CVSS details not available.
No product information available.
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 8.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L |
mitre | ||
| 3.1 | 8.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L |
nvd | ||
| 3.1 | 8.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L |
opencve |
No references available.
No linked vulnerabilities found.
{
"cve": "CVE-2026-87266",
"enrichment": {
"affected": [
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "semver",
"value": "9.3.6"
}
}
],
"enrichment": {
"confidence": 100.0,
"confidence_source": "inferred",
"scores": [
{
"score": 100.0,
"source": "inferred"
},
{
"score": 100.0,
"source": "matching"
}
]
},
"original": {
"product": "Oracle Agile PLM",
"source": "cna",
"vendor": "Oracle Corporation"
},
"product": "agile_plm",
"vendor": "oracle"
}
],
"created": "2026-09-16T08:45:19.058022+00:00",
"title": "Unauthenticated HTTP Exploit Exposes Data in Oracle Agile PLM 9.3.6",
"updated": "2026-09-20T05:30:16.750969+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$agile_plm"
]
},
"epss": {
"score": 0.00359
},
"mitre": {
"cpes": [
"cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*"
],
"created": "2026-09-15T20:06:33.552000+00:00",
"description": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 8.2,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L"
},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2026/87xxx/CVE-2026-87266.json",
"references": [
"https://www.oracle.com/security-alerts/cspusep2026.html"
],
"title": null,
"updated": "2026-09-18T14:46:53.739000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$agile_plm"
],
"weaknesses": []
},
"nvd": {
"cpes": [
"cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*"
],
"created": "2026-09-15T20:19:15.260000+00:00",
"description": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 8.2,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2026/CVE-2026-87266.json",
"references": [
"https://www.oracle.com/security-alerts/cspusep2026.html"
],
"title": null,
"updated": "2026-09-22T17:29:08.513000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$agile_product_lifecycle_management"
],
"weaknesses": [
"CWE-284"
]
},
"opencve": {
"changes": [
{
"created": "2026-09-15T20:15:00+00:00",
"data": [
{
"details": {
"new": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).",
"old": null
},
"type": "description"
},
{
"details": [
"oracle",
"oracle$PRODUCT$agile_plm"
],
"type": "first_time"
},
{
"details": {
"added": [
"cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"oracle",
"oracle$PRODUCT$agile_plm"
],
"removed": []
},
"type": "vendors"
},
{
"details": {
"added": [
"https://www.oracle.com/security-alerts/cspusep2026.html"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV3_1": {
"score": 8.2,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "28cad587-63aa-46fc-a4b8-45ab59c8773b"
},
{
"created": "2026-09-16T16:00:00+00:00",
"data": [
{
"details": {
"new": "Unauthenticated HTTP Access Exploit Allows Data Compromise in Oracle Agile PLM",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-284",
"CWE-307"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "75e7006f-a477-479b-8f5f-66de659cff57"
},
{
"created": "2026-09-18T21:30:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Unauthenticated HTTP Access Exploit Allows Data Compromise in Oracle Agile PLM"
},
"type": "title"
},
{
"details": {
"added": [],
"removed": [
"CWE-307"
]
},
"type": "weaknesses"
}
],
"id": "9b64363a-1339-4384-971b-fc5c238e99d1"
},
{
"created": "2026-09-20T03:30:00+00:00",
"data": [
{
"details": {
"added": {
"ssvc": {
"options": {
"Automatable": "yes",
"Exploitation": "none",
"Technical Impact": "partial"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "dc43b5ae-bb11-4ec4-a082-1323a2807e7c"
},
{
"created": "2026-09-20T05:45:00+00:00",
"data": [
{
"details": {
"new": "Unauthenticated HTTP Exploit Exposes Data in Oracle Agile PLM 9.3.6",
"old": null
},
"type": "title"
}
],
"id": "73c42fb1-fd84-43f1-a018-e2a6b320cd6e"
},
{
"created": "2026-09-22T17:45:00+00:00",
"data": [
{
"details": [
"oracle$PRODUCT$agile_product_lifecycle_management"
],
"type": "first_time"
},
{
"details": {
"added": [
"cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"oracle$PRODUCT$agile_product_lifecycle_management"
],
"removed": []
},
"type": "vendors"
}
],
"id": "7586d508-fe3e-43a1-9a7b-3042051a4212"
}
],
"cpes": {
"data": [
"cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*"
],
"providers": [
"mitre",
"nvd"
]
},
"created": {
"data": "2026-09-15T20:06:33.552000+00:00",
"provider": "mitre"
},
"description": {
"data": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 8.2,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L"
},
"provider": "mitre"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.00359
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {
"options": {
"Automatable": "yes",
"Exploitation": "none",
"Technical Impact": "partial"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://www.oracle.com/security-alerts/cspusep2026.html"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": "Unauthenticated HTTP Exploit Exposes Data in Oracle Agile PLM 9.3.6",
"provider": "enrichment"
},
"updated": {
"data": "2026-09-22T17:29:08.513000+00:00",
"provider": "nvd"
},
"vendors": {
"data": [
"oracle",
"oracle$PRODUCT$agile_plm",
"oracle$PRODUCT$agile_product_lifecycle_management"
],
"providers": [
"mitre",
"nvd",
"enrichment"
]
},
"weaknesses": {
"data": [
"CWE-284"
],
"providers": [
"nvd",
"vulnrichment"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2026-09-15T20:06:33.552000+00:00",
"description": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {},
"kev": {},
"ssvc": {
"options": {
"Automatable": "yes",
"Exploitation": "none",
"Technical Impact": "partial"
},
"version": "2.0.3"
}
},
"references": [],
"title": null,
"updated": "2026-09-18T13:58:27.563000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2026/87xxx/CVE-2026-87266.json",
"weaknesses": [
"CWE-284"
]
}
}