CVE-2026-71078 Overview
CVE-2026-71078 affects the Oracle Agile PLM MCAD Connector product within the Oracle Supply Chain suite. The flaw resides in the CAX Client component of version 3.6. A low-privileged attacker with local access to the infrastructure running Oracle Agile PLM MCAD Connector can exploit the weakness, though successful exploitation requires user interaction from a separate party. The vulnerability maps to [CWE-284] Improper Access Control.
Successful exploitation yields limited unauthorized read access, limited unauthorized update, insert, or delete access, and can cause a partial denial of service against the connector.
Critical Impact
Exploitation grants an authenticated local attacker limited read and write access to connector data and can induce a partial denial of service in Oracle Agile PLM MCAD Connector 3.6.
Affected Products
- Oracle Agile PLM MCAD Connector 3.6
- Component: CAX Client
- Product family: Oracle Supply Chain
Discovery Timeline
- 2026-08-18 - CVE-2026-71078 published to NVD
- 2026-08-20 - Last updated in NVD database
- Vendor advisory: Oracle Security Alert
Technical Details for CVE-2026-71078
Vulnerability Analysis
The vulnerability is classified as an Improper Access Control issue [CWE-284] within the CAX Client component of Oracle Agile PLM MCAD Connector 3.6. The CAX Client is the interface that brokers mechanical CAD design files and metadata between engineering workstations and the Agile PLM backend.
Exploitation is rated as difficult and requires the attacker to already possess low-privileged credentials on the infrastructure hosting the connector. The attack also requires human interaction from a user other than the attacker, such as opening a crafted design artifact or approving a triggered action.
When the required conditions align, the attacker gains partial impact across confidentiality, integrity, and availability. Data exposure is limited to a subset of connector-accessible information, while write operations are constrained to data the connector can modify.
Root Cause
Oracle's advisory attributes the issue to improper access control within the CAX Client. Access decisions inside the client do not fully constrain what a low-privileged local user can read, modify, or disrupt when a second user interacts with the connector.
Attack Vector
The attack vector is local. An authenticated user on the host running the MCAD Connector must trigger the vulnerable code path, and a separate user must perform an in-application action for the exploit to succeed. Oracle has not published exploitation details, and no public proof of concept is available. Refer to the Oracle Security Alert for vendor-supplied technical context.
Detection Methods for CVE-2026-71078
Indicators of Compromise
- Unexpected modification, insertion, or deletion of CAD metadata handled by the MCAD Connector.
- Anomalous read access by low-privileged local accounts to files or objects managed by the CAX Client.
- Partial or intermittent availability failures of the Oracle Agile PLM MCAD Connector service without a corresponding system fault.
Detection Strategies
- Enable and forward Oracle Agile PLM audit logs to a central log store for correlation of access-control anomalies.
- Baseline normal CAX Client process behavior on connector hosts and flag deviations in file access patterns.
- Correlate local logon events on connector infrastructure with CAX Client activity to identify unusual low-privileged usage.
Monitoring Recommendations
- Monitor for interactive logons by service or engineering accounts that should not access the connector host directly.
- Alert on repeated user-interaction prompts or dialog-driven workflows initiated by non-standard local users.
- Track integrity of CAD artifacts and PLM object attributes touched by the MCAD Connector against a known-good baseline.
How to Mitigate CVE-2026-71078
Immediate Actions Required
- Apply the fixes published in the Oracle Security Alert referenced in the August 2026 advisory bundle.
- Inventory all systems running Oracle Agile PLM MCAD Connector 3.6 and prioritize patching connector hosts that support engineering workflows.
- Restrict interactive and remote logon rights on connector infrastructure to a minimal set of administrators.
Patch Information
Oracle addresses this vulnerability in its August 2026 security update. Administrators should consult the vendor advisory at Oracle Security Alert to obtain patch identifiers and version guidance for Oracle Agile PLM MCAD Connector.
Workarounds
- Enforce least privilege on the connector host so only required engineering and service accounts retain local logon.
- Segment the MCAD Connector infrastructure from general user networks to reduce the pool of potential low-privileged attackers.
- Educate CAD and PLM users to avoid opening unexpected design artifacts or approving unfamiliar in-application prompts until patches are deployed.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

