Oracle has disclosed a critical vulnerability in the Event Java PX component of Oracle Agile PLM 9.3.6 that allows a network-based attacker to fully compromise the product and impact adjacent systems, scoring 9.1 on CVSS 3.1.
What Is It
CVE-2026-83260 is a vulnerability in the Oracle Agile PLM product of Oracle Supply Chain, specifically in the Event Java PX component. Oracle describes it as an easily exploitable flaw that allows a high-privileged attacker with network access via T3 or IIOP protocols to compromise Oracle Agile PLM. Successful exploitation results in complete takeover of the product.
The issue carries a CVSS 3.1 base score of 9.1 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, network attack vector, low attack complexity, no user interaction required, and high impact to confidentiality, integrity, and availability.
Why It Matters
The defining characteristic here is the scope change (S:C). Oracle explicitly notes that while the vulnerability resides in Agile PLM, attacks "may significantly impact additional products." A compromise may not stay contained to the PLM instance; depending on how the deployment is segmented and what trust it is granted, it can become a pivot into whatever else sits within the same trust boundary.
The exposure surface is also notable: T3 and IIOP are WebLogic-family remote protocols that are frequently reachable in internal deployments and, in poorly segmented environments, potentially from beyond them. Combined with low attack complexity and no user interaction, the practical barrier to exploitation is the high-privilege requirement (PR:H), a bar that credential theft, insider access, or a prior foothold can satisfy, though it does raise the cost of an attack relative to an unauthenticated flaw.
Agile PLM holds product lifecycle data: designs, bills of materials, supplier records, and engineering change history. Full takeover of the product implies access to that intellectual property, plus the ability to alter it.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Agile PLM (Oracle Supply Chain)
- Component: Event Java PX
- Affected version: 9.3.6 (the supported version affected)
- Attack path: Network access via T3, IIOP
No CPE data is currently listed in the NVD record.
Patch Status
The CVE record was published 2026-09-15 with NVD status Received: meaning it has not yet completed NVD analysis. The CVE record's vendor reference points to Oracle's security alerts site; note that the specific advisory path carried in the record does not resolve to a published Oracle advisory, and Oracle's security-alerts index should be treated as the authoritative source for fixed versions and patch guidance. Oracle's quarterly Critical Patch Updates and out-of-cycle Security Alerts are both published there.
CVE-2026-83260 does not appear in CISA's Known Exploited Vulnerabilities catalog at this time, so there is no confirmed active exploitation and no federally mandated remediation deadline associated with it. Because no Oracle advisory for this CVE currently resolves, organizations running Agile PLM 9.3.6 should monitor Oracle's security-alerts index for a fix and apply it, prioritized by the CVSS 9.1 rating, once one is published, and should restrict T3/IIOP network reachability in the meantime.