Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-83274

CVE-2026-83274: Oracle Agile PLM MCAD Connector Disclosure

CVE-2026-83274 is an information disclosure vulnerability in Oracle Agile PLM MCAD Connector that allows low-privileged attackers to access critical data. This post explains its technical details, affected versions, and mitigation.

Published:

CVE-2026-83274 Overview

CVE-2026-83274 affects the Oracle Agile PLM MCAD Connector, a component of the Oracle Supply Chain product family. The flaw resides in the CAX Client component of version 3.6. A low-privileged attacker with local logon access to the infrastructure where the connector executes can compromise the application. Successful exploitation results in unauthorized access to critical data or complete read access to all data accessible by the Oracle Agile PLM MCAD Connector. The vulnerability is classified as an information disclosure issue, with confidentiality being the only impacted security property. Oracle addressed this issue in its September 2026 Security Alert (CSPUSEP2026).

Critical Impact

A local, authenticated attacker can read all data accessible to the Oracle Agile PLM MCAD Connector, exposing sensitive product lifecycle and supply chain information.

Affected Products

  • Oracle Agile PLM MCAD Connector 3.6
  • Component: CAX Client
  • Product family: Oracle Supply Chain

Discovery Timeline

  • 2026-09-15 - CVE-2026-83274 published to the National Vulnerability Database (NVD)
  • 2026-09-16 - Last updated in NVD database

Technical Details for CVE-2026-83274

Vulnerability Analysis

The vulnerability exists in the CAX Client component of Oracle Agile PLM MCAD Connector 3.6. Oracle's advisory categorizes the flaw as easily exploitable by an attacker who already holds low privileges on the host executing the connector. Exploitation does not require user interaction and does not cross a security boundary. The impact is limited to confidentiality: an attacker can read data managed by or accessible to the connector, but cannot modify data or disrupt availability. Because Agile PLM manages product lifecycle information, exposed data may include intellectual property, mechanical CAD files, bill-of-materials records, and supplier information.

Root Cause

Oracle has not publicly disclosed the specific weakness class, and no CWE identifier is assigned. Based on the CVSS metrics and the local, authenticated attack profile, the flaw is consistent with an information exposure condition in the CAX Client where sensitive data is accessible to a local user account that should not have access. Consult the Oracle Security Alert CSPUSEP2026 for vendor-provided technical detail.

Attack Vector

The attack vector is local. An attacker must first authenticate to the host where the Oracle Agile PLM MCAD Connector runs, typically a workstation used by mechanical engineers integrating CAD tools with Agile PLM. Once authenticated with low privileges, the attacker can invoke the vulnerable code path in the CAX Client component to obtain unauthorized read access to data the connector processes. No network access, elevated privileges, or user interaction is required to complete the attack.

No public proof-of-concept exploit or exploitation-in-the-wild activity has been reported for CVE-2026-83274 at the time of publication.

Detection Methods for CVE-2026-83274

Indicators of Compromise

  • Unexpected process activity from the Oracle Agile PLM MCAD Connector CAX Client executable running under non-engineering user contexts.
  • Unusual read access to Agile PLM cache directories, temporary CAD extraction folders, or connector configuration files by unprivileged local accounts.
  • Anomalous file staging or archive creation in user profile directories on hosts that run the connector.

Detection Strategies

  • Baseline the accounts that legitimately interact with the Oracle Agile PLM MCAD Connector and alert on access by accounts outside that baseline.
  • Monitor for local interactive or remote-desktop logons on engineering workstations followed by access to connector data paths.
  • Correlate file access events on Agile PLM data locations with process ancestry to identify off-pattern readers of connector data.

Monitoring Recommendations

  • Enable file system auditing on directories used by the Oracle Agile PLM MCAD Connector and forward events to a centralized log platform.
  • Track privileged and service account usage on hosts running the connector, including logon type and session duration.
  • Ingest Oracle Agile PLM application logs alongside endpoint telemetry to correlate connector-side activity with host-side behavior.

How to Mitigate CVE-2026-83274

Immediate Actions Required

  • Apply the patch released in Oracle Security Alert CSPUSEP2026 to all deployments of Oracle Agile PLM MCAD Connector 3.6.
  • Inventory all workstations and servers running the connector to confirm patch coverage.
  • Restrict interactive logon rights on hosts executing the connector to engineers who require access.
  • Review recent local logon events on affected hosts for unexpected accounts.

Patch Information

Oracle addressed CVE-2026-83274 in the September 2026 Security Alert bundle (CSPUSEP2026). Administrators should download the applicable patch for Oracle Agile PLM MCAD Connector 3.6 from My Oracle Support and apply it following the vendor's deployment guidance. Refer to the Oracle Security Alert CSPUSEP2026 for the complete patch matrix and installation instructions.

Workarounds

  • Enforce least-privilege on hosts running the connector so that only authorized engineering accounts can log on locally.
  • Apply file system access control lists to Agile PLM MCAD Connector data directories, restricting read access to required users only.
  • Isolate engineering workstations that run the connector on a segmented network with restricted lateral movement paths.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.