Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-71088

CVE-2026-71088: Oracle Agile PLM Information Disclosure

CVE-2026-71088 is an information disclosure vulnerability in Oracle Agile PLM MCAD Connector that allows attackers to access critical data. This article covers technical details, affected versions, impact, and mitigation.

Updated:

CVE-2026-71088 Overview

CVE-2026-71088 affects the Oracle Agile PLM MCAD Connector, a component of the Oracle Supply Chain product family. The flaw resides in the CAX Client component of version 3.6. A low-privileged attacker with network access over HTTP can exploit the issue, though successful exploitation requires user interaction from a victim other than the attacker. Successful attacks can result in unauthorized read access to critical data or full access to all data accessible through the Oracle Agile PLM MCAD Connector. Oracle disclosed the issue in the Oracle Security Alert Advisory for August 2026.

Critical Impact

Successful exploitation exposes all data accessible through the Oracle Agile PLM MCAD Connector, breaching product lifecycle management confidentiality.

Affected Products

  • Oracle Agile PLM MCAD Connector 3.6
  • Component: CAX Client
  • Oracle Supply Chain product family

Discovery Timeline

Technical Details for CVE-2026-71088

Vulnerability Analysis

The vulnerability affects the CAX Client component of the Oracle Agile PLM Mechanical Computer-Aided Design (MCAD) Connector. The connector integrates MCAD tools with Oracle Agile Product Lifecycle Management (PLM), handling design files, part metadata, and revision data. Exploitation requires a network-accessible HTTP path, a low-privileged Oracle account, and a separate user action performed by a victim.

The impact is limited to confidentiality. Integrity and availability are not affected. An attacker who succeeds gains read access to data within the MCAD Connector scope, which typically includes design documents, bill-of-materials records, and product change data. Oracle categorizes exploitation complexity as high, indicating that specific preconditions must align for the attack chain to succeed.

Root Cause

Oracle has not published a public CWE mapping or detailed technical breakdown for this issue. The advisory only confirms that a low-privileged, authenticated attacker can trigger unauthorized data disclosure through the HTTP interface of the CAX Client when a second user performs an action such as opening a crafted link or artifact.

Attack Vector

The attack path begins with a low-privileged authenticated session against the Oracle Agile PLM MCAD Connector. The attacker crafts an HTTP request or artifact that requires interaction from another user. When the second user interacts with the attacker-supplied content, the connector discloses data the attacker would not otherwise access. No verified public proof-of-concept exists. Refer to the Oracle Security Alert August 2026 for vendor-supplied details.

Detection Methods for CVE-2026-71088

Indicators of Compromise

  • Unexpected HTTP requests to the Oracle Agile PLM MCAD Connector CAX Client endpoints from low-privileged accounts.
  • Access logs showing one user initiating a request that returns data owned by or scoped to another user session.
  • Outbound retrieval of MCAD design files or PLM metadata by accounts without a documented business need.

Detection Strategies

  • Monitor authentication logs for MCAD Connector sessions initiated by low-privileged users followed by anomalous data reads.
  • Correlate HTTP request patterns against known Agile PLM MCAD Connector 3.6 endpoints to identify crafted URLs targeting other users.
  • Alert on unusual volumes of file or metadata downloads from the CAX Client component outside baseline usage windows.

Monitoring Recommendations

  • Forward Oracle Agile PLM MCAD Connector web and application logs to a centralized analytics platform for retention and correlation.
  • Baseline normal user access patterns to design and change records, and alert on deviations.
  • Track privileged and low-privileged account activity separately to surface lateral read attempts across user scopes.

How to Mitigate CVE-2026-71088

Immediate Actions Required

  • Apply the fixes referenced in the Oracle Security Alert August 2026 to Oracle Agile PLM MCAD Connector 3.6.
  • Inventory all deployments of the MCAD Connector and confirm patch status across environments.
  • Restrict network reachability of the connector to trusted internal networks or VPN-bound clients.
  • Review and reduce the population of accounts with access to the CAX Client component.

Patch Information

Oracle addressed the issue in the August 2026 Security Alert cycle. Administrators should consult the Oracle Security Alert August 2026 for patch identifiers, applicability details, and installation guidance specific to Oracle Agile PLM MCAD Connector 3.6.

Workarounds

  • Limit MCAD Connector HTTP exposure using network segmentation and firewall rules until patching is complete.
  • Enforce user awareness guidance so operators do not interact with unsolicited links or artifacts referencing the connector.
  • Rotate credentials for low-privileged accounts if suspicious access patterns are observed prior to patch deployment.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.