SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61171 2026-07-21

CVE-2026-61171: Critical Unauthenticated Flaw in Oracle Agile PLM

"A critical, easily exploitable vulnerability in Oracle Agile PLM allows unauthenticated network attackers to read and alter all data accessible to the application, earning a CVSS 3.1 base score of 9.1."

A critical, easily exploitable vulnerability in Oracle Agile PLM allows unauthenticated network attackers to read and alter all data accessible to the application, earning a CVSS 3.1 base score of 9.1.

What Is It

CVE-2026-61171 is a vulnerability in the Security component of Oracle Agile PLM, part of the Oracle Supply Chain product family. According to Oracle's advisory, the flaw is easily exploitable and lets an unauthenticated attacker with network access over HTTP compromise Oracle Agile PLM. The CVSS vector, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, reflects network attack vector, low complexity, no privileges, and no user interaction, with high confidentiality and integrity impact.

Why It Matters

Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, up to all data accessible within Oracle Agile PLM, as well as unauthorized read access to that data. Because the attack requires no authentication and no user interaction, a network-reachable instance is exposed to remote compromise. The 9.1 CRITICAL base score is driven by the combined high confidentiality and integrity impact; availability is not affected per the vector.

What's Vulnerable

No CPE match strings were listed in the NVD record at time of publication.

Patch Status

The vulnerability was published on 2026-07-21 with a status of "Received" and is referenced against Oracle's July 2026 Critical Patch Update. Administrators should consult Oracle's Critical Patch Update advisory for the corresponding fix and apply it. No CISA KEV entry was supplied, so active exploitation is not confirmed in the source material provided.

Sources