CVE-2026-61172
Oracle Agile PLM vulnerability analysis and mitigation

Overview

CVE-2026-61172 is an authentication bypass vulnerability in the Security component of Oracle Agile PLM (Product Lifecycle Management), part of Oracle Supply Chain. The affected version is 9.3.6. An unauthenticated remote attacker can exploit this vulnerability over HTTP to gain unauthorized access to critical data within Oracle Agile PLM. It was disclosed on July 21, 2026, as part of Oracle's Critical Patch Update (CPU) for July 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Oracle Advisory).

Technical details

The vulnerability resides in the Security component of Oracle Agile PLM version 9.3.6, classified as an authentication bypass (CWE not explicitly assigned, but consistent with improper authentication controls). The attack vector is network-based via HTTP, requires no privileges and no user interaction, and has low attack complexity — making it easily exploitable by unauthenticated attackers. Successful exploitation allows an attacker to bypass authentication controls and access all data within the PLM system. No detailed technical write-ups or public proof-of-concept code have been identified at this time (Oracle Advisory).

Impact

Exploitation of this vulnerability results in a complete confidentiality breach of Oracle Agile PLM data, including potentially sensitive product lifecycle, engineering, and supply chain information. There is no integrity or availability impact reported. An unauthenticated attacker with network access could gain full read access to all data accessible within the Oracle Agile PLM application, which may include proprietary product designs, supplier data, and regulated information (Oracle Advisory).

Mitigation and workarounds

Oracle has released a security patch for Oracle Agile PLM version 9.3.6 as part of the July 2026 Critical Patch Update, and immediate application is strongly recommended. As an interim measure if patching is not immediately possible, organizations should restrict network access to Oracle Agile PLM to authorized IP addresses and users, and consider deploying a Web Application Firewall (WAF) to filter suspicious HTTP traffic. Oracle advises against relying on network-level controls as a long-term solution, as they do not address the underlying vulnerability (Oracle Advisory).

Additional resources


SourceThis report was generated using AI

Related Oracle Agile PLM vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61171CRITICAL9.1
  • Oracle Agile PLM logoOracle Agile PLM
  • cpe:2.3:a:oracle:agile_plm
NoNoJul 21, 2026
CVE-2026-61170HIGH8.1
  • Oracle Agile PLM logoOracle Agile PLM
  • cpe:2.3:a:oracle:agile_plm
NoNoJul 21, 2026
CVE-2026-61172HIGH7.5
  • Oracle Agile PLM logoOracle Agile PLM
  • cpe:2.3:a:oracle:agile_plm
NoNoJul 21, 2026
CVE-2026-61173HIGH7.4
  • Oracle Agile PLM logoOracle Agile PLM
  • cpe:2.3:a:oracle:agile_plm
NoNoJul 21, 2026
CVE-2026-61169MEDIUM6.5
  • Oracle Agile PLM logoOracle Agile PLM
  • cpe:2.3:a:oracle:agile_plm
NoNoJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management