ZeroHour

CVE-2026-83277

niche

Local Privilege Escalation in Oracle Agile PLM MCAD Connector 3.6 (CAX Client)

CVSS 3.1
7.3 high
EPSS
Published
()
Modified
AI analysis

A local privilege escalation vulnerability in the CAX Client component of Oracle Agile PLM MCAD Connector 3.6 (part of Oracle Supply Chain products) allows a low-privileged attacker with a logon to the host where the connector executes to fully compromise the connector. The flaw carries a scope change, meaning successful attacks can significantly impact additional products beyond the connector itself. A successful exploit grants unauthorized creation, deletion, or modification of critical data or all connector-accessible data, plus unauthorized read access to a subset of that data (CVSS 3.1: 7.3, AV:L/AC:L/PR:L/UI:N/S:C, with low confidentiality and high integrity impact and no availability impact). Affected organizations are primarily large manufacturers running Oracle Agile PLM with the MCAD Connector installed on CAD engineering workstations. No public proof-of-concept is known, the CVE is not on CISA's KEV list, and there is no evidence of in-the-wild exploitation.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83277 to all installations of Agile PLM MCAD Connector 3.6. Because exploitation requires only a low-privileged local logon, restrict interactive and remote-desktop access to engineering workstations hosting the CAX Client and minimize local account provisioning. Review Agile PLM data for unauthorized modifications or deletions and audit connector hosts for suspicious activity by low-privileged users.

Affected
Oracle Agile PLM MCAD Connector (component: CAX Client)
Estimated exposure
nicheunknown — plausibly low thousands of enterprise deployments and CAD-engineer workstations — No public install counts or internet-exposure data exist; Oracle Agile PLM is enterprise product-lifecycle-management software used mainly by large manufacturers, so the workstation-side CAD connector footprint is limited to those…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. While the vulnerability is in Oracle Agile PLM MCAD Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM MCAD Connector accessible data as well as unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N).

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N

In the news

No ingested article mentions this CVE yet.