Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-71072

CVE-2026-71072: Oracle Agile PLM MCAD Connector DOS Vulnerability

CVE-2026-71072 is a denial of service vulnerability in Oracle Agile PLM MCAD Connector that allows low privileged attackers to cause partial service disruption. This article covers technical details, affected versions, and mitigation.

Updated:

CVE-2026-71072 Overview

CVE-2026-71072 affects the Oracle Agile PLM MCAD Connector, a component of Oracle Supply Chain. The flaw resides in the CAX Client component of version 3.6. A low-privileged attacker with logon access to the infrastructure where the connector executes can compromise the product. Successful exploitation results in a partial denial of service (DoS) of the Oracle Agile PLM MCAD Connector. The weakness maps to CWE-284 (Improper Access Control) and impacts availability only, with no confidentiality or integrity impact.

Critical Impact

A locally authenticated attacker can trigger a partial denial of service against Oracle Agile PLM MCAD Connector 3.6, disrupting engineering change workflows tied to Agile PLM.

Affected Products

  • Oracle Agile PLM MCAD Connector 3.6
  • Component: CAX Client
  • Oracle Supply Chain product family

Discovery Timeline

Technical Details for CVE-2026-71072

Vulnerability Analysis

The vulnerability affects the CAX Client component of Oracle Agile PLM MCAD Connector 3.6. This connector bridges mechanical computer-aided design (MCAD) tools with the Agile Product Lifecycle Management (PLM) platform. The defect allows a low-privileged local user to disrupt connector availability. Impact is limited to availability. Confidentiality and integrity remain intact based on the published CVSS vector. Because the connector often participates in product data management workflows, an outage can stall check-in and check-out operations against Agile PLM.

Root Cause

The issue is categorized as [CWE-284] Improper Access Control. Oracle's advisory does not publish source-level details. The classification indicates that the CAX Client does not adequately restrict an authenticated local principal from performing an action that degrades service availability. Oracle has not released additional technical specifics beyond the August 2026 Critical Patch Update.

Attack Vector

Exploitation requires local access to the host running the Oracle Agile PLM MCAD Connector. The attacker must possess valid credentials with low privileges on that system. No user interaction is required. Attack complexity is low, making the flaw straightforward to trigger once local authenticated access is obtained. Remote exploitation over a network is not possible based on the CVSS vector.

No verified public exploit code is available for CVE-2026-71072. Refer to the Oracle Security Alert for authoritative remediation guidance.

Detection Methods for CVE-2026-71072

Indicators of Compromise

  • Unexpected process termination or crash events for the Oracle Agile PLM MCAD Connector CAX Client on host systems.
  • Repeated service restarts or connector reinitialization in Oracle Agile PLM application logs.
  • Interruptions in MCAD-to-PLM synchronization workflows without corresponding administrative activity.

Detection Strategies

  • Monitor operating system event logs on hosts running the MCAD Connector for abnormal termination of the CAX Client process.
  • Correlate authenticated local logon events with connector availability degradation using an EDR or SIEM.
  • Baseline normal connector uptime and alert on deviations that align with local user session activity.

Monitoring Recommendations

  • Enable process creation and termination auditing on Windows hosts running Oracle Agile PLM MCAD Connector 3.6.
  • Forward connector service logs and Windows Security event logs to a centralized log platform for correlation.
  • Track interactive and remote logon activity against the connector host and alert on low-privileged accounts interacting with connector binaries.

How to Mitigate CVE-2026-71072

Immediate Actions Required

  • Apply the fixes referenced in the Oracle Critical Patch Update August 2026 for Oracle Agile PLM MCAD Connector.
  • Inventory all installations of Oracle Agile PLM MCAD Connector 3.6 and prioritize patching for production supply chain systems.
  • Restrict interactive logon rights on hosts running the connector to trusted administrative personnel only.

Patch Information

Oracle addressed CVE-2026-71072 in the August 2026 Critical Patch Update. Administrators should review the Oracle Security Alert August 2026 for the specific patch bundle applicable to Oracle Agile PLM MCAD Connector 3.6 and apply it during the next maintenance window.

Workarounds

  • Limit local logon on connector hosts to a small set of vetted administrator accounts until the patch is applied.
  • Apply least-privilege principles to service accounts that interact with the CAX Client component.
  • Segment connector hosts on the network to reduce the population of users able to authenticate locally.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.