Vulnerability in Oracle Agile PLM Affecting Oracle Supply Chain
CVE-2026-87258

7.6HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87258?

A security vulnerability in the Oracle Agile PLM within the Oracle Supply Chain system allows low privileged attackers with network access to HTTP to breach security. This exploitable flaw requires interaction from a user other than the attacker, posing significant risks to data confidentiality and integrity. Successful exploitation can lead to unauthorized access to sensitive data, including the ability to update, insert, or delete critical data within the Oracle Agile PLM ecosystem, potentially affecting other interconnected products.

Affected Version(s)

Oracle Agile PLM 9.3.6

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.