CVE-2026-71072 Overview
CVE-2026-71072 affects the Oracle Agile PLM MCAD Connector, a component of Oracle Supply Chain. The flaw resides in the CAX Client component of version 3.6. A low-privileged attacker with logon access to the infrastructure where the connector executes can compromise the product. Successful exploitation results in a partial denial of service (DoS) of the Oracle Agile PLM MCAD Connector. The weakness maps to CWE-284 (Improper Access Control) and impacts availability only, with no confidentiality or integrity impact.
Critical Impact
A locally authenticated attacker can trigger a partial denial of service against Oracle Agile PLM MCAD Connector 3.6, disrupting engineering change workflows tied to Agile PLM.
Affected Products
- Oracle Agile PLM MCAD Connector 3.6
- Component: CAX Client
- Oracle Supply Chain product family
Discovery Timeline
- 2026-08-18 - CVE-2026-71072 published to NVD
- 2026-08-20 - Last updated in NVD database
- August 2026 - Disclosed in the Oracle Security Alert August 2026
Technical Details for CVE-2026-71072
Vulnerability Analysis
The vulnerability affects the CAX Client component of Oracle Agile PLM MCAD Connector 3.6. This connector bridges mechanical computer-aided design (MCAD) tools with the Agile Product Lifecycle Management (PLM) platform. The defect allows a low-privileged local user to disrupt connector availability. Impact is limited to availability. Confidentiality and integrity remain intact based on the published CVSS vector. Because the connector often participates in product data management workflows, an outage can stall check-in and check-out operations against Agile PLM.
Root Cause
The issue is categorized as [CWE-284] Improper Access Control. Oracle's advisory does not publish source-level details. The classification indicates that the CAX Client does not adequately restrict an authenticated local principal from performing an action that degrades service availability. Oracle has not released additional technical specifics beyond the August 2026 Critical Patch Update.
Attack Vector
Exploitation requires local access to the host running the Oracle Agile PLM MCAD Connector. The attacker must possess valid credentials with low privileges on that system. No user interaction is required. Attack complexity is low, making the flaw straightforward to trigger once local authenticated access is obtained. Remote exploitation over a network is not possible based on the CVSS vector.
No verified public exploit code is available for CVE-2026-71072. Refer to the Oracle Security Alert for authoritative remediation guidance.
Detection Methods for CVE-2026-71072
Indicators of Compromise
- Unexpected process termination or crash events for the Oracle Agile PLM MCAD Connector CAX Client on host systems.
- Repeated service restarts or connector reinitialization in Oracle Agile PLM application logs.
- Interruptions in MCAD-to-PLM synchronization workflows without corresponding administrative activity.
Detection Strategies
- Monitor operating system event logs on hosts running the MCAD Connector for abnormal termination of the CAX Client process.
- Correlate authenticated local logon events with connector availability degradation using an EDR or SIEM.
- Baseline normal connector uptime and alert on deviations that align with local user session activity.
Monitoring Recommendations
- Enable process creation and termination auditing on Windows hosts running Oracle Agile PLM MCAD Connector 3.6.
- Forward connector service logs and Windows Security event logs to a centralized log platform for correlation.
- Track interactive and remote logon activity against the connector host and alert on low-privileged accounts interacting with connector binaries.
How to Mitigate CVE-2026-71072
Immediate Actions Required
- Apply the fixes referenced in the Oracle Critical Patch Update August 2026 for Oracle Agile PLM MCAD Connector.
- Inventory all installations of Oracle Agile PLM MCAD Connector 3.6 and prioritize patching for production supply chain systems.
- Restrict interactive logon rights on hosts running the connector to trusted administrative personnel only.
Patch Information
Oracle addressed CVE-2026-71072 in the August 2026 Critical Patch Update. Administrators should review the Oracle Security Alert August 2026 for the specific patch bundle applicable to Oracle Agile PLM MCAD Connector 3.6 and apply it during the next maintenance window.
Workarounds
- Limit local logon on connector hosts to a small set of vetted administrator accounts until the patch is applied.
- Apply least-privilege principles to service accounts that interact with the CAX Client component.
- Segment connector hosts on the network to reduce the population of users able to authenticate locally.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

