
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-61172 is an authentication bypass vulnerability in the Security component of Oracle Agile PLM (Product Lifecycle Management), part of Oracle Supply Chain. The affected version is 9.3.6. An unauthenticated remote attacker can exploit this vulnerability over HTTP to gain unauthorized access to critical data within Oracle Agile PLM. It was disclosed on July 21, 2026, as part of Oracle's Critical Patch Update (CPU) for July 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Oracle Advisory).
The vulnerability resides in the Security component of Oracle Agile PLM version 9.3.6, classified as an authentication bypass (CWE not explicitly assigned, but consistent with improper authentication controls). The attack vector is network-based via HTTP, requires no privileges and no user interaction, and has low attack complexity — making it easily exploitable by unauthenticated attackers. Successful exploitation allows an attacker to bypass authentication controls and access all data within the PLM system. No detailed technical write-ups or public proof-of-concept code have been identified at this time (Oracle Advisory).
Exploitation of this vulnerability results in a complete confidentiality breach of Oracle Agile PLM data, including potentially sensitive product lifecycle, engineering, and supply chain information. There is no integrity or availability impact reported. An unauthenticated attacker with network access could gain full read access to all data accessible within the Oracle Agile PLM application, which may include proprietary product designs, supplier data, and regulated information (Oracle Advisory).
Oracle has released a security patch for Oracle Agile PLM version 9.3.6 as part of the July 2026 Critical Patch Update, and immediate application is strongly recommended. As an interim measure if patching is not immediately possible, organizations should restrict network access to Oracle Agile PLM to authorized IP addresses and users, and consider deploying a Web Application Firewall (WAF) to filter suspicious HTTP traffic. Oracle advises against relying on network-level controls as a long-term solution, as they do not address the underlying vulnerability (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."