HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-46859Published Modified CNA oracle

CVE-2026-46859: Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security)

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
9.8
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An authentication bypass and full-system takeover vulnerability exists in the Security component of Oracle Agile PLM version 9.3.6, part of the Oracle Supply Chain suite. The flaw is reachable over a standard HTTP network connection with no credentials required and no user interaction needed, making it trivially exploitable by any attacker who can reach the service. Successful exploitation results in complete takeover of the Oracle Agile PLM instance, giving the attacker full control over confidentiality, integrity, and availability. No fix version has been published yet; HarborGuard tracks this advisory and will make a patched-image rebuild available the moment Oracle ships an upstream fix.

HarborGuard Coverage

Detection

Detection for CVE-2026-46859 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that package Oracle Agile PLM 9.3.6 components.

Available
Triage

HarborGuard is capable of scoring this CVE at its published CVSS 3.1 base score of 9.8 (Critical) and weighting findings against each environment's compliance policy to surface the alert to the appropriate team or inbox within the customer organization.

Available
Patch

No fix version has been published by Oracle for this CVE. HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released; customers with auto-remediation enabled will receive the rebuilt image, a regression-test run, and a pull request opened against affected workloads without manual intervention.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must be able to reach the Oracle Agile PLM service over the network via HTTP; AV:N means any host with network access to the exposed endpoint is in scope.

  • AuthenticationNot required

    No credentials of any kind are needed; PR:N means an unauthenticated attacker can send a direct exploit payload to the service.

  • Victim interactionNot required

    No user action is required; UI:N means the attack completes without any interaction from a logged-in user or administrator.

  • Attack complexityDetail

    Attack complexity is Low (AC:L), meaning the exploit is reliable and repeatable with no dependency on race conditions, memory layout, or other environmental factors.

Blast Radius

  • A successful attacker reads all data stored in Oracle Agile PLM, including product lifecycle records, design files, supplier data, and stored credentials.
  • The attacker can modify or delete persisted PLM records, corrupt product definitions, and tamper with supply chain workflows.
  • The attacker can crash or render the Oracle Agile PLM service unavailable, disrupting any business process that depends on it.
  • Full system takeover means the attacker can establish persistent access, pivot to connected systems on the same network segment, and exfiltrate data continuously.

How HarborGuard Handles This

Available on HarborGuard: this CVE is flagged Critical at CVSS 9.8 and receives priority treatment in the detection pipeline, with matching against all images containing Oracle Agile PLM 9.3.6 components running within minutes of advisory ingestion. Because Oracle has not yet published a fix version, no patched-image rebuild can be generated at this time. HarborGuard monitors the advisory on every ingest cycle and will make a rebuilt image available automatically once Oracle ships an upstream patch; for customers with auto-remediation enabled, that triggers a regression-test run and a pull request opened against affected workloads. In the interim, customers are encouraged to apply compensating controls where policy permits: isolate Oracle Agile PLM instances behind a network policy that restricts inbound HTTP access to known internal IP ranges, apply egress filtering to limit lateral movement if the host is compromised, and consider disabling externally exposed PLM endpoints until a patch is available.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Oracle Agile PLM
    9.3.6
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References