CVE-2026-61167 Overview
CVE-2026-61167 is an unauthenticated remote vulnerability in the Security component of Oracle Agile PLM, part of the Oracle Supply Chain product family. The affected supported version is 9.3.6. An attacker with network access over HTTP can compromise the application without credentials or user interaction. Successful exploitation results in full takeover of Oracle Agile PLM, impacting confidentiality, integrity, and availability. Oracle disclosed the issue in the Oracle Critical Patch Update Advisory - July 2026.
Critical Impact
Unauthenticated attackers can achieve complete takeover of Oracle Agile PLM 9.3.6 over the network via HTTP, compromising all product lifecycle management data and workflows.
Affected Products
- Oracle Agile PLM 9.3.6
- Oracle Supply Chain product family (Security component)
- Deployments exposing the Agile PLM HTTP interface
Discovery Timeline
- 2026-07-21 - CVE-2026-61167 published to NVD
- 2026-07-21 - Last updated in NVD database
- July 2026 - Oracle publishes fix in the July 2026 Critical Patch Update
Technical Details for CVE-2026-61167
Vulnerability Analysis
The vulnerability resides in the Security component of Oracle Agile PLM, the product lifecycle management platform used to coordinate engineering data, bill-of-materials, and supplier collaboration. Oracle categorizes the flaw as easily exploitable by a remote, unauthenticated attacker with HTTP access to the application.
Successful exploitation grants the attacker complete control of the Agile PLM instance. Because Agile PLM stores intellectual property, product designs, and supplier records, a compromise exposes proprietary data and can be used as a pivot into connected ERP and manufacturing systems. Oracle has not published low-level technical details beyond the advisory to protect customers who have not yet patched.
Root Cause
Oracle attributes the flaw to the Security component of Agile PLM 9.3.6. The advisory indicates no authentication or user interaction is required, and the attack complexity is low. This pattern is consistent with an authentication or authorization bypass in the HTTP-facing tier of the application. Oracle's advisory is the authoritative source for the root cause.
Attack Vector
The attack vector is network based over HTTP. An attacker sends crafted requests to the Agile PLM web tier without prior credentials. Because Agile PLM instances are often reachable from internal corporate networks and, in some deployments, from partner-facing extranets, the exposed attack surface can be broad. No verified public exploit is currently listed; the current EPSS probability is 0.486%.
See the Oracle Critical Patch Update Advisory - July 2026 for the vendor's technical details and patch mapping.
Detection Methods for CVE-2026-61167
Indicators of Compromise
- Unauthenticated HTTP requests to Agile PLM endpoints followed by administrative actions in application logs.
- Creation of new Agile PLM user accounts, roles, or privilege assignments without a corresponding change ticket.
- Unexpected outbound connections from the Agile PLM application server to unknown hosts.
- Access to sensitive product records or bill-of-materials data outside normal business hours or user patterns.
Detection Strategies
- Review Agile PLM application and web server logs for anomalous request patterns targeting the Security component.
- Alert on privileged operations initiated by sessions that lack a prior successful authentication event.
- Correlate web tier access logs with database audit logs to identify data access without a matching user login.
- Baseline normal HTTP traffic to Agile PLM and flag surges from a single source or from geographies unrelated to the business.
Monitoring Recommendations
- Forward Agile PLM, application server, and reverse proxy logs to a centralized analytics platform for retention and correlation.
- Monitor the underlying host for unexpected child processes spawned by the Agile PLM Java application server.
- Track integrity of Agile PLM configuration files and deployed application archives for unauthorized modification.
How to Mitigate CVE-2026-61167
Immediate Actions Required
- Apply the July 2026 Oracle Critical Patch Update for Agile PLM 9.3.6 as soon as change windows permit.
- Inventory all Agile PLM instances, including non-production copies, and confirm patch status for each.
- Restrict network access to Agile PLM HTTP endpoints to trusted management networks and known partner ranges only.
- Review recent Agile PLM administrative activity for signs of prior exploitation before patching.
Patch Information
Oracle addressed CVE-2026-61167 in the July 2026 Critical Patch Update. Refer to the Oracle Security Alert July 2026 for the specific patch identifiers, prerequisites, and installation order for Agile PLM 9.3.6.
Workarounds
- Place Agile PLM behind an authenticating reverse proxy or VPN to eliminate unauthenticated internet exposure.
- Apply web application firewall rules that block anonymous access to Security component URLs pending patch deployment.
- Disable or firewall external interfaces that are not required for business operations until the patch is applied.
- Rotate Agile PLM administrative credentials and integration secrets after patching if exposure is suspected.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

