Vulnerability in Oracle Agile PLM MCAD Connector from Oracle
CVE-2026-71088

4.8MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71088?

A low privileged attacker with network access via HTTP may exploit the Oracle Agile PLM MCAD Connector, allowing unauthorized access to sensitive data. The attack relies on human interaction, making it potentially deceptive and difficult to track. Victims could suffer from significant data exposure without rigorous security measures in place. It is crucial to review system access protocols to mitigate risks associated with this vulnerability.

Affected Version(s)

Oracle Agile PLM MCAD Connector 3.6

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.