CVE-2026-87266
nicheUnauthenticated data exposure and partial DoS in Oracle Agile PLM 9.3.6
Oracle Agile PLM 9.3.6 (Application Server component of Oracle Supply Chain) contains an easily exploitable flaw reachable over HTTP that requires no authentication, no user interaction, and no privileges. A remote attacker who can reach the application server over the network can trigger the flaw to gain unauthorized access to critical data — up to complete access to all Oracle Agile PLM accessible data — and can cause a partial denial of service. The issue is scored CVSS 3.1 8.2 (high), with high confidentiality impact and low availability impact but no integrity impact. Organizations running the affected 9.3.6 release, especially any instance reachable from the internet, are at risk of sensitive product-lifecycle, engineering, and supply-chain data disclosure. No public proof of concept is known and the CVE is not on CISA's KEV list, so exploitation is not currently observed.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87266 to all Agile PLM 9.3.6 Application Server instances, obtainable via My Oracle Support. Verify that no Agile PLM application server is exposed to the public internet — place it behind a VPN or restrict access at the firewall to trusted networks. Review access and HTTP server logs around the application server for anomalous unauthenticated requests or large data retrieval, and rotate credentials for accounts with access to Agile PLM data.
| Oracle Agile PLM (Application Server component, Oracle Supply Chain) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.