Unauthorized Access Vulnerability in Oracle Agile PLM MCAD Connector
CVE-2026-71071

4.6MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71071?

A vulnerability exists in the Oracle Agile PLM MCAD Connector, where a low-privileged attacker with access to the physical communication segment can exploit the system. This could lead to unauthorized updates, inserts, or deletions of data within the Oracle Agile PLM MCAD Connector. Furthermore, the attacker may gain unauthorized read access to a subset of accessible data. The security implications of this flaw underscore the importance of securing physical access to the hardware where this application operates. For more information, refer to the Oracle Advisory.

Affected Version(s)

Oracle Agile PLM MCAD Connector 3.6

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.