Vulnerability in Oracle Agile PLM MCAD Connector Affecting Oracle Supply Chain
CVE-2026-71078

4.2MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71078?

The Oracle Agile PLM MCAD Connector is exposed to an authentication-related vulnerability that could potentially be exploited by low-privileged attackers who have accessed the infrastructure where the product operates. This vulnerability necessitates human interaction from an individual other than the attacker to be successfully exploited. If compromised, an attacker may gain unauthorized access to update, insert, or delete specific data within the Oracle Agile PLM MCAD Connector. Additionally, this may allow unauthorized read access to certain data and the capability to induce a partial denial of service, affecting the availability of the product.

Affected Version(s)

Oracle Agile PLM MCAD Connector 3.6

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.