
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-61170 is a vulnerability in the Security component of Oracle Agile PLM (Product Lifecycle Management), part of Oracle Supply Chain Products. It affects version 9.3.6 and allows an unauthenticated attacker with network access via HTTP to fully compromise the application. The vulnerability was disclosed on July 21, 2026, as part of Oracle's Critical Patch Update (CPU) for July 2026. It carries a CVSS v3.1 base score of 8.1 (High) (Oracle Advisory).
The vulnerability resides in the Security component of Oracle Agile PLM version 9.3.6, exploitable remotely over HTTP without authentication. It is classified as a difficult-to-exploit (High Attack Complexity) network-based vulnerability requiring no privileges or user interaction, consistent with CWE patterns involving authentication bypass or insecure security controls. The specific root cause has not been publicly disclosed by Oracle, which follows its standard policy of not releasing detailed vulnerability analysis. No public technical write-ups or proof-of-concept code have been identified at this time (Oracle Advisory).
Successful exploitation can result in complete takeover of the Oracle Agile PLM instance, with high impacts to confidentiality, integrity, and availability. An attacker could read sensitive product lifecycle and supply chain data, modify or delete information, and disrupt service availability. Given that Agile PLM is commonly used to manage sensitive intellectual property and product data, exploitation could have significant downstream consequences for affected organizations (Oracle Advisory).
Oracle has released a patch for this vulnerability as part of the July 2026 Critical Patch Update (CPU), and organizations running Oracle Agile PLM 9.3.6 should apply it immediately. As a temporary workaround, Oracle recommends restricting network access to the Agile PLM application by blocking HTTP access from untrusted networks using firewall rules or network segmentation. Oracle strongly cautions that network-level blocking is not a long-term solution and does not address the underlying vulnerability. Organizations should also monitor for unauthorized access attempts against the Agile PLM instance (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."