CVE-2026-71070 Overview
CVE-2026-71070 affects the Oracle Agile PLM MCAD Connector product within Oracle Supply Chain, specifically the CAX Client component. The vulnerability exists in version 3.6 and allows a low-privileged attacker with network access via HTTP to compromise the connector. Successful exploitation results in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data. Oracle disclosed this issue in the Oracle Security Alert August 2026.
Critical Impact
An authenticated network attacker can read all data accessible to the Oracle Agile PLM MCAD Connector, exposing engineering, product lifecycle, and supply chain information.
Affected Products
- Oracle Agile PLM MCAD Connector
- CAX Client component
- Version 3.6
Discovery Timeline
- 2026-08-18 - CVE-2026-71070 published to the National Vulnerability Database (NVD)
- 2026-08-20 - CVE-2026-71070 last updated in NVD
Technical Details for CVE-2026-71070
Vulnerability Analysis
The vulnerability resides in the CAX Client component of the Oracle Agile PLM MCAD Connector. Oracle classifies the issue as easily exploitable over HTTP by an attacker holding low privileges on the target environment. Exploitation impacts confidentiality only; integrity and availability of the system remain unaffected according to Oracle's advisory.
Oracle Agile PLM MCAD Connector integrates mechanical computer-aided design (MCAD) tools with the Agile Product Lifecycle Management (PLM) platform. A confidentiality breach in this connector can expose sensitive product designs, bills of materials, and supply chain records.
Root Cause
Oracle has not published detailed root cause information beyond the Oracle Security Alert August 2026. The advisory categorizes the flaw as an information disclosure issue reachable through HTTP by an authenticated low-privileged user, indicating an access control or input handling weakness in the CAX Client.
Attack Vector
The attack originates from the network, requires no user interaction, and leverages an authenticated session with minimal privileges. An attacker sends crafted HTTP requests to the CAX Client interface to retrieve data outside the attacker's authorized scope. No public proof-of-concept exploit code is available for this vulnerability. Refer to the vendor advisory for technical remediation details.
Detection Methods for CVE-2026-71070
Indicators of Compromise
- Unusual HTTP request volume from low-privileged accounts to the CAX Client endpoint of the Oracle Agile PLM MCAD Connector.
- Requests targeting object identifiers or resource paths outside the account's assigned project scope.
- Bulk retrieval of design files, item records, or attachments by accounts that historically perform low read activity.
Detection Strategies
- Enable HTTP access logging on the Oracle Agile PLM MCAD Connector and forward logs to a centralized analytics platform for baseline analysis.
- Correlate authentication events with data access events to flag privilege inconsistencies between the user role and the data returned.
- Alert on any session that enumerates identifiers sequentially or downloads assets across multiple product families in a short window.
Monitoring Recommendations
- Monitor outbound egress from the connector host for large data transfers to non-corporate destinations.
- Track configuration and account provisioning changes on the Agile PLM stack to detect unauthorized privilege grants.
- Review access reports for the CAX Client component on a recurring basis and validate against approved user entitlements.
How to Mitigate CVE-2026-71070
Immediate Actions Required
- Apply the patch from the Oracle Security Alert August 2026 to affected Oracle Agile PLM MCAD Connector 3.6 deployments.
- Inventory all instances of the MCAD Connector and confirm version 3.6 status through change management records.
- Rotate credentials for low-privileged service and user accounts that access the CAX Client component.
Patch Information
Oracle released a fix as part of the August 2026 Security Alert cycle. Administrators should download the patch from My Oracle Support and follow the deployment steps published in the advisory. Validate patch application by confirming the connector build number after installation.
Workarounds
- Restrict HTTP access to the Oracle Agile PLM MCAD Connector to trusted management networks using firewall rules or reverse-proxy access controls.
- Enforce the principle of least privilege by reviewing role assignments and removing unnecessary access to the CAX Client component.
- Require multi-factor authentication and session logging for all accounts that reach the connector interface.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

