ZeroHour

CVE-2026-87266

niche

Unauthenticated data exposure and partial DoS in Oracle Agile PLM 9.3.6

CVSS 3.1
8.2 high
EPSS
Published
()
Modified
AI analysis

Oracle Agile PLM 9.3.6 (Application Server component of Oracle Supply Chain) contains an easily exploitable flaw reachable over HTTP that requires no authentication, no user interaction, and no privileges. A remote attacker who can reach the application server over the network can trigger the flaw to gain unauthorized access to critical data — up to complete access to all Oracle Agile PLM accessible data — and can cause a partial denial of service. The issue is scored CVSS 3.1 8.2 (high), with high confidentiality impact and low availability impact but no integrity impact. Organizations running the affected 9.3.6 release, especially any instance reachable from the internet, are at risk of sensitive product-lifecycle, engineering, and supply-chain data disclosure. No public proof of concept is known and the CVE is not on CISA's KEV list, so exploitation is not currently observed.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87266 to all Agile PLM 9.3.6 Application Server instances, obtainable via My Oracle Support. Verify that no Agile PLM application server is exposed to the public internet — place it behind a VPN or restrict access at the firewall to trusted networks. Review access and HTTP server logs around the application server for anomalous unauthenticated requests or large data retrieval, and rotate credentials for accounts with access to Agile PLM data.

Affected
Oracle Agile PLM (Application Server component, Oracle Supply Chain)
Estimated exposure
nichelikely a few thousand installations globally, with only hundreds internet-exposed — Oracle Agile PLM is enterprise-licensed, on-premise software deployed by a bounded set of large manufacturers, and public internet scans typically show only a few hundred exposed Agile PLM application servers.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.