Unauthenticated Access Vulnerability in Oracle Agile PLM Web Client by Oracle
CVE-2026-87253

6.1MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87253?

A vulnerability in the Oracle Agile PLM Web Client allows unauthorized network access to the system. This flaw can be exploited by an unauthenticated attacker with HTTP network access, requiring interaction from an unsuspecting user. Successful exploitation may lead to unauthorized operations, including updates, inserts, or deletions of data, and in some cases, unauthorized reading of sensitive information. This vulnerability poses a risk that could extend beyond Oracle Agile PLM, impacting other interrelated systems.

Affected Version(s)

Oracle Agile PLM 9.3.6

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.