
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21940 is an information disclosure vulnerability in the Oracle Agile PLM product (component: User and User Group) within Oracle Supply Chain. The affected version is 9.3.6. An unauthenticated attacker with network access via HTTP can exploit this vulnerability to gain unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. It was disclosed on January 20, 2026, as part of Oracle's Critical Patch Update (CPU) for January 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Oracle CPU Jan 2026).
The vulnerability is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), indicating that the application improperly exposes sensitive data to actors without proper authorization (Oracle CPU Jan 2026). The attack vector is network-based via HTTP, requires no privileges, no user interaction, and has low attack complexity — making it easily exploitable by unauthenticated remote attackers. The flaw resides in the User and User Group component of Oracle Agile PLM, suggesting an authentication bypass or improper access control mechanism that allows unauthorized enumeration or retrieval of user-related data. No public technical write-ups or proof-of-concept code have been identified at this time.
Successful exploitation allows an unauthenticated remote attacker to read critical data or gain complete access to all data accessible within Oracle Agile PLM, resulting in a high confidentiality impact. There is no integrity or availability impact reported. Given that Oracle Agile PLM manages product lifecycle data — including sensitive engineering, supply chain, and compliance information — unauthorized data access could expose proprietary product designs, supplier details, and regulated data to adversaries (Oracle CPU Jan 2026).
Oracle has released a security patch for this vulnerability as part of the January 2026 Critical Patch Update, available on January 20, 2026. Organizations running Oracle Agile PLM version 9.3.6 should apply the patch immediately (Oracle CPU Jan 2026). As a temporary workaround prior to patching, Oracle recommends blocking network protocols required by the attack (HTTP access to the affected component) and restricting access to Oracle Agile PLM to authorized networks and users only via network-level access controls. Monitoring access logs for unusual authentication attempts or abnormal data access patterns is also advised.
The vulnerability received limited but notable social media attention shortly after disclosure, with mentions on Mastodon and Bluesky via TheHackerWire, and coverage by automated CVE alert services such as RedPacket Security. No significant researcher commentary or in-depth technical analysis has been publicly published. Community reaction has been largely informational, noting the unauthenticated nature of the flaw and the availability of a patch.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."