Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Thu, 20 Aug 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized Data Exposure via Physical Access in Oracle Agile PLM MCAD Connector |
Thu, 20 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized Data Exposure via Physical Access in Oracle Agile PLM MCAD Connector |
Thu, 20 Aug 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Physical Access Exploitation in Oracle Agile PLM MCAD Connector | |
| Weaknesses | CWE-200 CWE-287 |
Wed, 19 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Wed, 19 Aug 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Physical Access Exploitation in Oracle Agile PLM MCAD Connector | |
| Weaknesses | CWE-200 CWE-287 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N). | |
| First Time appeared |
Oracle
Oracle agile Plm Mcad Connector |
|
| CPEs | cpe:2.3:a:oracle:agile_plm_mcad_connector:3.6:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle agile Plm Mcad Connector |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-08-18T21:03:23.792Z
Updated: 2026-08-19T16:03:10.546Z
Reserved: 2026-08-04T22:06:34.615Z
Link: CVE-2026-71077
Updated: 2026-08-19T15:01:07.713Z
Status : Analyzed
Published: 2026-08-18T21:18:07.837
Modified: 2026-08-24T17:08:10.620
Link: CVE-2026-71077
No data.