CVE-2026-21940
Oracle Agile PLM vulnerability analysis and mitigation

Overview

CVE-2026-21940 is an information disclosure vulnerability in the Oracle Agile PLM product (component: User and User Group) within Oracle Supply Chain. The affected version is 9.3.6. An unauthenticated attacker with network access via HTTP can exploit this vulnerability to gain unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. It was disclosed on January 20, 2026, as part of Oracle's Critical Patch Update (CPU) for January 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Oracle CPU Jan 2026).

Technical details

The vulnerability is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), indicating that the application improperly exposes sensitive data to actors without proper authorization (Oracle CPU Jan 2026). The attack vector is network-based via HTTP, requires no privileges, no user interaction, and has low attack complexity — making it easily exploitable by unauthenticated remote attackers. The flaw resides in the User and User Group component of Oracle Agile PLM, suggesting an authentication bypass or improper access control mechanism that allows unauthorized enumeration or retrieval of user-related data. No public technical write-ups or proof-of-concept code have been identified at this time.

Impact

Successful exploitation allows an unauthenticated remote attacker to read critical data or gain complete access to all data accessible within Oracle Agile PLM, resulting in a high confidentiality impact. There is no integrity or availability impact reported. Given that Oracle Agile PLM manages product lifecycle data — including sensitive engineering, supply chain, and compliance information — unauthorized data access could expose proprietary product designs, supplier details, and regulated data to adversaries (Oracle CPU Jan 2026).

Mitigation and workarounds

Oracle has released a security patch for this vulnerability as part of the January 2026 Critical Patch Update, available on January 20, 2026. Organizations running Oracle Agile PLM version 9.3.6 should apply the patch immediately (Oracle CPU Jan 2026). As a temporary workaround prior to patching, Oracle recommends blocking network protocols required by the attack (HTTP access to the affected component) and restricting access to Oracle Agile PLM to authorized networks and users only via network-level access controls. Monitoring access logs for unusual authentication attempts or abnormal data access patterns is also advised.

Community reactions

The vulnerability received limited but notable social media attention shortly after disclosure, with mentions on Mastodon and Bluesky via TheHackerWire, and coverage by automated CVE alert services such as RedPacket Security. No significant researcher commentary or in-depth technical analysis has been publicly published. Community reaction has been largely informational, noting the unauthenticated nature of the flaw and the availability of a patch.

Additional resources


SourceThis report was generated using AI

Related Oracle Agile PLM vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61171CRITICAL9.1
  • Oracle Agile PLM logoOracle Agile PLM
  • cpe:2.3:a:oracle:agile_plm
NoNoJul 21, 2026
CVE-2026-61170HIGH8.1
  • Oracle Agile PLM logoOracle Agile PLM
  • cpe:2.3:a:oracle:agile_plm
NoNoJul 21, 2026
CVE-2026-61172HIGH7.5
  • Oracle Agile PLM logoOracle Agile PLM
  • cpe:2.3:a:oracle:agile_plm
NoNoJul 21, 2026
CVE-2026-61173HIGH7.4
  • Oracle Agile PLM logoOracle Agile PLM
  • cpe:2.3:a:oracle:agile_plm
NoNoJul 21, 2026
CVE-2026-61169MEDIUM6.5
  • Oracle Agile PLM logoOracle Agile PLM
  • cpe:2.3:a:oracle:agile_plm
NoNoJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management