A critical (CVSS 9.8) vulnerability in Oracle Agile PLM lets an unauthenticated attacker fully compromise the product over the network via HTTP.
What Is It
CVE-2026-61167 is a critical vulnerability in the Security component of Oracle Agile PLM, part of the Oracle Supply Chain product family. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful exploitation can result in complete takeover of the product.
The issue carries a CVSS 3.1 base score of 9.8 (Critical) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of no authentication, low attack complexity, and full compromise makes this among the most severe classes of vulnerability. An attacker needs only network HTTP access to the affected system, no credentials and no user interaction, to take over Oracle Agile PLM, a product commonly deployed to manage product lifecycle and supply chain data. The maximum impact ratings across confidentiality, integrity, and availability mean an attacker could read, alter, and destroy data or disrupt the service entirely.
What's Vulnerable
- Product: Oracle Agile PLM (Oracle Supply Chain), Security component
- Vendor: Oracle Corporation
- Affected version: 9.3.6
No proof of active exploitation is included in the supplied source material; there is no CISA KEV entry accompanying this record.
Patch Status
Oracle addressed this issue in its July 2026 Critical Patch Update (CPU). Organizations running Oracle Agile PLM 9.3.6 should apply the fixes referenced in the Oracle July 2026 Critical Patch Update advisory. Given the CVSS 9.8 rating and unauthenticated network exploitability, patching should be prioritized.