CVE-2026-71081
Analyzed Analyzed - Analysis Complete

Privilege Escalation in Oracle Agile PLM MCAD Connector

Vulnerability report for CVE-2026-71081, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-08-24

Assigner: Oracle

Description

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 1.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-08-24
Generated
2026-09-08
AI Q&A
2026-08-19
EPSS Evaluated
2026-09-07
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
oracle agile_plm_mcad_connector 3.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in Oracle Agile PLM MCAD Connector version 3.6. It allows a highly privileged attacker with local system access to potentially modify or delete some data within the application. The impact is limited to integrity, meaning data could be altered but not fully compromised or exposed.

Detection Guidance

Detection of this vulnerability requires identifying systems running Oracle Agile PLM MCAD Connector version 3.6. Check installed software versions on systems where the connector is deployed. Review system logs for unusual activity related to data access or modifications in the Oracle Agile PLM MCAD Connector environment.

Impact Analysis

If you use Oracle Agile PLM MCAD Connector 3.6, an attacker with high privileges and local access could change or delete some of your data. This could disrupt operations or lead to incorrect data being used in your systems.

Compliance Impact

This vulnerability may impact compliance by allowing unauthorized data modifications, which could violate integrity requirements in standards like GDPR or HIPAA. However, the limited scope (local access, high privileges) reduces the overall risk to compliance.

Mitigation Strategies

Apply the latest security patches or updates provided by Oracle for the Agile PLM MCAD Connector. Restrict user privileges to the minimum required for operation. Monitor and audit data access and modifications within the Oracle Agile PLM MCAD Connector environment.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71081. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart