Vulnerability in Oracle Agile PLM MCAD Connector Product of Oracle Supply Chain
CVE-2026-71066

4.5MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71066?

A vulnerability exists in the Oracle Agile PLM MCAD Connector product, specifically in the CAX Client component. It allows attackers with access to the infrastructure where the connector operates to potentially exploit the system, provided they are accompanied by human interaction from an unsuspecting third party. This could lead to unauthorized modifications, inserts, or deletions of data stored within the Oracle Agile PLM system. Additionally, attackers may gain unauthorized read access to certain data, jeopardizing information confidentiality and integrity, and may also trigger partial denial of service conditions, affecting the connector's availability.

Affected Version(s)

Oracle Agile PLM MCAD Connector 3.6

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.