ZeroHour

CVE-2026-83260

niche

Privileged Remote Takeover via T3/IIOP in Oracle Agile PLM 9.3.6 Event Java PX

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

Oracle Agile PLM 9.3.6 contains a critical flaw (CVSS 9.1) in the Event Java PX (Process Extension) component that a high-privileged attacker with network access can exploit over the T3 or IIOP protocols to fully take over the Agile PLM server. Because the vulnerability has a scope change, a successful attack can also significantly impact products beyond Agile PLM itself, with high impact on confidentiality, integrity, and availability. Exploitation is described as easy once the attacker holds the required high privileges, which effectively turns any compromised admin account or trusted network foothold into complete server compromise. The affected population is enterprises running the on-premises Oracle Agile PLM 9.3.6 release, common in manufacturing and product-development environments. No public proof-of-concept exists and the flaw is not in the CISA Known Exploited Vulnerabilities catalog, so there is no evidence of in-the-wild exploitation at this time.

What to do: Apply the corresponding Oracle Critical Patch Update to Agile PLM 9.3.6 as soon as it is available for this CVE. In the meantime, restrict T3 and IIOP listener access at the firewall to trusted admin clients only, since the flaw requires high privileges — audit privileged Agile/WebLogic accounts and rotate credentials that may be exposed. Review deployed Event Java PX extensions and server logs for unauthorized changes or suspicious T3/IIOP activity, and accelerate planning to migrate off the aging 9.3.6 line toward Oracle Fusion Cloud PLM.

Affected
Oracle Agile PLM (Oracle Supply Chain, component: Event Java PX)
Estimated exposure
nichelikely low-thousands of on-prem enterprise installations worldwide; internet-exposed T3/IIOP endpoints likely only in the hundreds — Oracle Agile PLM is a legacy on-premises enterprise PLM suite deployed by manufacturing firms with no public install counts, and only a small fraction of such deployments typically expose WebLogic T3/IIOP listeners directly to the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Event Java PX). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows high privileged attacker with network access via T3, IIOP to compromise Oracle Agile PLM. While the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.