Summary
CVE-2026-71040 is a critical, remotely exploitable vulnerability in Oracle Agile PLM, classified under CWE-284 (Improper Access Control) in the product’s Security component. It allows an unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM, with the potential for complete takeover of the application. Oracle rates the flaw 9.8 (Critical) on the CVSS v3.1 scale, reflecting full loss of confidentiality, integrity, and availability with no authentication or user interaction required.
Technical details
- Root cause: Improper access control (CWE-284) in the Security component of Oracle Agile PLM, allowing access-control checks to be bypassed.
- Trigger conditions: The vulnerability is exploitable by an attacker who merely has network access to the application over HTTP — no valid credentials or user interaction are needed.
- Attack vector: Network (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: Successful exploitation can result in complete compromise of Oracle Agile PLM, with high impact to confidentiality, integrity, and availability (C:H/I:H/A:H) — effectively full takeover of the application and the data it manages.
Affected software
- Oracle Agile PLM (Oracle Supply Chain) — version 9.3.6
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s Critical Patch Update for August 2026, which addresses CVE-2026-71040 for Oracle Agile PLM 9.3.6. Organizations should apply the patch as soon as possible per Oracle’s guidance.
- If immediate patching is not possible: Restrict network access to Agile PLM instances (e.g., limit exposure to trusted internal networks or VPN-only access, place behind a web application firewall) to reduce the risk of unauthenticated remote exploitation until the patch can be applied. These are general compensating controls, not a substitute for patching.

