CVE-2026-61170 Overview
CVE-2026-61170 is a high-severity vulnerability in the Oracle Agile PLM product within the Oracle Supply Chain suite. The flaw resides in the Security component of Oracle Agile PLM version 9.3.6. An unauthenticated attacker with network access via HTTP can exploit the weakness to compromise the affected system. Successful exploitation results in complete takeover of Oracle Agile PLM, impacting confidentiality, integrity, and availability. Oracle disclosed the issue in the Oracle Security Alert July 2026. While exploitation requires overcoming complexity conditions, the network-based attack path and lack of authentication requirements make this vulnerability a priority for supply chain security teams.
Critical Impact
Unauthenticated network attackers can achieve full takeover of Oracle Agile PLM 9.3.6, compromising confidentiality, integrity, and availability of product lifecycle data.
Affected Products
- Oracle Agile PLM 9.3.6
- Oracle Supply Chain (Agile PLM component)
- Security component of Oracle Agile PLM
Discovery Timeline
- 2026-07-21 - CVE CVE-2026-61170 published to NVD
- 2026-07-21 - Oracle Security Alert July 2026 released
- 2026-07-21 - Last updated in NVD database
Technical Details for CVE-2026-61170
Vulnerability Analysis
The vulnerability affects the Security component of Oracle Agile PLM 9.3.6, a product lifecycle management platform used to manage engineering data and supply chain processes. Oracle's advisory categorizes the issue as difficult to exploit but network-reachable over HTTP without any authentication. Successful exploitation grants an attacker full takeover of the Agile PLM instance, meaning the adversary can read, alter, and destroy managed product data.
Because Agile PLM stores intellectual property, bill-of-materials data, and engineering change orders, a takeover has downstream consequences for manufacturing and supply chain integrity. Oracle has not published a detailed technical write-up. The advisory confirms unauthenticated network access via HTTP is sufficient once the exploitation preconditions are met.
Root Cause
Oracle attributes the flaw to the Security component of Agile PLM 9.3.6. The advisory does not disclose the underlying weakness class or associated CWE identifier. Refer to the Oracle Security Alert July 2026 for authoritative details as Oracle releases additional information.
Attack Vector
Exploitation occurs remotely over HTTP against an exposed Oracle Agile PLM instance. The attacker requires no credentials and no user interaction. Attack complexity is elevated, indicating specific conditions or timing must align for successful compromise. Organizations that expose Agile PLM to untrusted networks face the greatest risk. Once compromised, the attacker gains control over the application, which Oracle equates to full product takeover.
No public proof-of-concept exploit code is available at time of publication, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.
Detection Methods for CVE-2026-61170
Indicators of Compromise
- Unexpected authentication events or administrative account creation within Oracle Agile PLM audit logs.
- Anomalous outbound connections originating from the Agile PLM application server.
- Unusual modifications to product records, bill-of-materials data, or change orders outside normal engineering workflows.
- HTTP requests to Agile PLM endpoints from unrecognized source addresses or user agents.
Detection Strategies
- Baseline normal HTTP traffic patterns to Agile PLM and alert on deviations, especially unauthenticated requests to security-related endpoints.
- Monitor Agile PLM application and web server logs for repeated failed requests followed by successful privileged actions.
- Correlate file system, process, and network telemetry from the Agile PLM host to identify post-exploitation activity such as new processes or shells.
Monitoring Recommendations
- Ingest Agile PLM application, web server, and database logs into a centralized SIEM for continuous review.
- Enable and retain HTTP access logs and audit trails with sufficient retention to support incident investigations.
- Alert on privilege changes, role modifications, and administrative operations performed outside change-control windows.
How to Mitigate CVE-2026-61170
Immediate Actions Required
- Apply the July 2026 Oracle Critical Patch Update for Agile PLM 9.3.6 as described in the Oracle Security Alert July 2026.
- Inventory all Oracle Agile PLM 9.3.6 deployments, including test and disaster recovery instances.
- Restrict network reachability to Agile PLM so that only trusted internal networks and VPN users can access the HTTP interface.
- Review Agile PLM audit logs for signs of unauthorized access or configuration changes.
Patch Information
Oracle addressed CVE-2026-61170 in the July 2026 Critical Patch Update. Administrators should follow Oracle's patch guidance for Agile PLM 9.3.6 and validate patch application through the Oracle inventory tooling. Refer to the Oracle Security Alert July 2026 for the authoritative patch matrix and installation instructions.
Workarounds
- Place Agile PLM behind a reverse proxy or web application firewall that enforces authentication and blocks anonymous access to security endpoints.
- Segment Agile PLM servers into a dedicated network zone with strict ingress and egress filtering.
- Disable or restrict any Agile PLM services that are not required for business operations to reduce attack surface until patching completes.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

