Network Vulnerability in Oracle Agile PLM Affects Oracle Supply Chain Products
CVE-2026-87254

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87254?

A network vulnerability in the Oracle Agile PLM component of Oracle Supply Chain impacts the ability to safeguard sensitive data. Specifically, the flaw allows a low privileged attacker with network access via HTTP to potentially exploit the product. If leveraged, this vulnerability could lead to unauthorized takeover of the Oracle Agile PLM system. Users should prioritize updating to the latest software version to mitigate security risks associated with this issue.

Affected Version(s)

Oracle Agile PLM 9.3.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.