Application Server Vulnerability in Oracle Agile PLM by Oracle
CVE-2026-87256

7.7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87256?

A vulnerability has been identified in Oracle's Agile PLM product within the Application Server component. This issue allows low-privileged attackers with network access via HTTP to gain unauthorized access to sensitive information. Although the vulnerability is specific to Oracle Agile PLM version 9.3.6, it has the potential to impact other related products, which may lead to significant data exposure. Successful exploitation could enable attackers to access critical data stored within Agile PLM, posing a considerable risk to data security and integrity.

Affected Version(s)

Oracle Agile PLM 9.3.6

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.