Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-61168

CVE-2026-61168: Oracle Agile PLM Auth Bypass Vulnerability

CVE-2026-61168 is an authentication bypass vulnerability in Oracle Agile PLM 9.3.6 that enables low-privileged attackers to take over the system. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2026-61168 Overview

CVE-2026-61168 is a high-severity vulnerability in the Oracle Agile PLM product of Oracle Supply Chain. The flaw resides in the Security component of Oracle Agile PLM version 9.3.6. An authenticated attacker with low privileges and network access via HTTP can exploit this vulnerability. Successful exploitation results in full takeover of the Oracle Agile PLM instance, compromising confidentiality, integrity, and availability. Oracle addressed the issue in the July 2026 Critical Patch Update.

Critical Impact

Successful exploitation allows a low-privileged, authenticated attacker to fully take over Oracle Agile PLM, exposing sensitive product lifecycle data and enterprise supply chain records.

Affected Products

  • Oracle Agile PLM (Oracle Supply Chain)
  • Oracle Agile PLM version 9.3.6
  • Security component of Oracle Agile PLM

Discovery Timeline

  • 2026-07-21 - CVE-2026-61168 published to NVD
  • 2026-07-21 - Last updated in NVD database
  • July 2026 - Oracle releases fix in the July 2026 Critical Patch Update

Technical Details for CVE-2026-61168

Vulnerability Analysis

CVE-2026-61168 affects the Security component of Oracle Agile PLM 9.3.6, a Product Lifecycle Management (PLM) application used to manage product data, engineering changes, and supply chain records. The vulnerability is exploitable over the network using HTTP and requires only low-level authentication with no user interaction. An attacker who exploits the flaw gains complete control over the application, including all product data stored in it.

Oracle classifies the impact as high across confidentiality, integrity, and availability. Because Agile PLM often stores intellectual property such as bill of materials, engineering drawings, and supplier data, a successful compromise carries significant business risk. The EPSS score reported at publication was 0.447%.

Root Cause

Oracle has not published detailed root-cause information beyond identifying the Security component of Oracle Agile PLM 9.3.6 as the affected subsystem. The advisory indicates that the flaw allows a low-privileged authenticated attacker to escalate control and take over the application. Refer to the Oracle July 2026 Security Alert for vendor guidance.

Attack Vector

The attack originates from the network over HTTP against an exposed Oracle Agile PLM 9.3.6 instance. The attacker must hold valid low-privileged credentials but does not need user interaction. Once authenticated, the attacker sends crafted HTTP requests to the Security component to trigger the takeover condition. The scope remains unchanged, meaning the compromise is contained to Oracle Agile PLM but grants full control over that application.

No verified proof-of-concept exploit is publicly available at the time of publication. See the Oracle July 2026 Security Alert for details.

Detection Methods for CVE-2026-61168

Indicators of Compromise

  • Unexpected administrative changes within Oracle Agile PLM performed by low-privileged accounts.
  • Anomalous HTTP requests targeting Oracle Agile PLM Security component endpoints from unusual internal or external sources.
  • Sudden creation of new privileged users, role assignments, or configuration changes in Agile PLM audit logs.
  • Exfiltration patterns involving bulk downloads of BOM data, engineering files, or supplier records.

Detection Strategies

  • Monitor Oracle Agile PLM application logs and web server access logs for authenticated sessions performing privilege-changing operations.
  • Correlate authentication events with subsequent administrative actions to identify low-privileged accounts performing high-privilege functions.
  • Deploy web application firewall (WAF) rules to alert on abnormal HTTP request patterns targeting Agile PLM endpoints.

Monitoring Recommendations

  • Enable and centralize Oracle Agile PLM audit logs into a SIEM for correlation with network and identity telemetry.
  • Baseline normal user behavior in Agile PLM and alert on deviations such as off-hours access or geographic anomalies.
  • Track outbound network flows from Agile PLM servers to detect unauthorized data staging or transfer.

How to Mitigate CVE-2026-61168

Immediate Actions Required

  • Apply the patches published in the Oracle July 2026 Critical Patch Update to Oracle Agile PLM 9.3.6 without delay.
  • Inventory all Oracle Agile PLM deployments and confirm version 9.3.6 systems are prioritized for patching.
  • Rotate credentials for all Agile PLM user accounts, particularly service and integration accounts, after patching.
  • Review Agile PLM audit logs for signs of prior exploitation before completing remediation.

Patch Information

Oracle released fixes for CVE-2026-61168 as part of the July 2026 Critical Patch Update. Administrators should review the Oracle July 2026 Security Alert for patch bundles, prerequisites, and application instructions specific to Oracle Agile PLM 9.3.6.

Workarounds

  • Restrict network access to Oracle Agile PLM to trusted internal segments using firewall or VPN controls.
  • Enforce strict least-privilege on Agile PLM user roles and disable inactive or unnecessary accounts.
  • Place a reverse proxy or WAF in front of Agile PLM to inspect and filter HTTP traffic to the Security component.
  • Enable multi-factor authentication on all identity providers used to access Agile PLM.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.