CVE-2026-61170
Oracle Agile PLM vulnerability analysis and mitigation

Overview

CVE-2026-61170 is a vulnerability in the Security component of Oracle Agile PLM (Product Lifecycle Management), part of Oracle Supply Chain Products. It affects version 9.3.6 and allows an unauthenticated attacker with network access via HTTP to fully compromise the application. The vulnerability was disclosed on July 21, 2026, as part of Oracle's Critical Patch Update (CPU) for July 2026. It carries a CVSS v3.1 base score of 8.1 (High) (Oracle Advisory).

Technical details

The vulnerability resides in the Security component of Oracle Agile PLM version 9.3.6, exploitable remotely over HTTP without authentication. It is classified as a difficult-to-exploit (High Attack Complexity) network-based vulnerability requiring no privileges or user interaction, consistent with CWE patterns involving authentication bypass or insecure security controls. The specific root cause has not been publicly disclosed by Oracle, which follows its standard policy of not releasing detailed vulnerability analysis. No public technical write-ups or proof-of-concept code have been identified at this time (Oracle Advisory).

Impact

Successful exploitation can result in complete takeover of the Oracle Agile PLM instance, with high impacts to confidentiality, integrity, and availability. An attacker could read sensitive product lifecycle and supply chain data, modify or delete information, and disrupt service availability. Given that Agile PLM is commonly used to manage sensitive intellectual property and product data, exploitation could have significant downstream consequences for affected organizations (Oracle Advisory).

Mitigation and workarounds

Oracle has released a patch for this vulnerability as part of the July 2026 Critical Patch Update (CPU), and organizations running Oracle Agile PLM 9.3.6 should apply it immediately. As a temporary workaround, Oracle recommends restricting network access to the Agile PLM application by blocking HTTP access from untrusted networks using firewall rules or network segmentation. Oracle strongly cautions that network-level blocking is not a long-term solution and does not address the underlying vulnerability. Organizations should also monitor for unauthorized access attempts against the Agile PLM instance (Oracle Advisory).

Additional resources


SourceThis report was generated using AI

Related Oracle Agile PLM vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61171CRITICAL9.1
  • Oracle Agile PLM logoOracle Agile PLM
  • cpe:2.3:a:oracle:agile_plm
NoNoJul 21, 2026
CVE-2026-61170HIGH8.1
  • Oracle Agile PLM logoOracle Agile PLM
  • cpe:2.3:a:oracle:agile_plm
NoNoJul 21, 2026
CVE-2026-61172HIGH7.5
  • Oracle Agile PLM logoOracle Agile PLM
  • cpe:2.3:a:oracle:agile_plm
NoNoJul 21, 2026
CVE-2026-61173HIGH7.4
  • Oracle Agile PLM logoOracle Agile PLM
  • cpe:2.3:a:oracle:agile_plm
NoNoJul 21, 2026
CVE-2026-61169MEDIUM6.5
  • Oracle Agile PLM logoOracle Agile PLM
  • cpe:2.3:a:oracle:agile_plm
NoNoJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management