PatchSiren cyber security CVE debrief
CVE-2026-83274 Oracle Corporation CVE debrief
A vulnerability exists in Oracle Agile PLM MCAD Connector, a medium-severity issue allowing low-privileged attackers with logon access to compromise the system and gain unauthorized access to critical data. This vulnerability, tracked as CVE-2026-83274, affects version 3.6 of the product and has a CVSS 3.1 Base Score of 5.5, indicating a significant risk to confidentiality. Defenders responsible for deployments should assess exposure and prioritize remediation efforts to prevent potential data breaches.
- Vendor
- Oracle Corporation
- Product
- Oracle Agile PLM MCAD Connector
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-21
Who should care
Defenders responsible for Oracle Agile PLM MCAD Connector deployments should assess exposure and prioritize remediation efforts to prevent potential data breaches. This includes reviewing and applying security patches, restricting access to the infrastructure, and monitoring for suspicious activity. Additionally, security teams and vulnerability management teams should be aware of the potential impact on their systems and take appropriate measures to mitig
Why it matters
CVE-2026-83274 is a medium-severity vulnerability in Oracle Agile PLM MCAD Connector that allows low-privileged attackers to gain unauthorized access to critical data. Defenders responsible for Oracle Agile PLM MCAD Connector deployments should assess exposure and prioritize remediation.
- Verify and restrict access to the infrastructure where Oracle Agile PLM MCAD Connector executes.
- Monitor for suspicious activity and implement compensating controls to protect sensitive data.
- Apply Oracle's security patches for Oracle Agile PLM MCAD Connector version 3.6.
Technical summary
The vulnerability in Oracle Agile PLM MCAD Connector, component: CAX Client, allows a low-privileged attacker with logon access to compromise the system and gain unauthorized access to critical data. The CVSS 3.1 Base Score is 5.5 (Confidentiality impacts). This medium-severity vulnerability affects version 3.6 of the product and has a CVSS vector of (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). Defenders should focus on applying patches and restricting access to mitigate the risk of data breaches. The vulnerability's technical details are grounded in the official CVE and NVD sources, which provide a comprehensive assessment of the issue.
Defensive priority
Medium
Recommended defensive actions
- Review and apply Oracle's security patches for Oracle Agile PLM MCAD Connector version 3.6.
- Restrict access to the infrastructure where Oracle Agile PLM MCAD Connector executes.
- Monitor for suspicious activity and implement compensating controls to protect sensitive data.
- Verify and restrict access to the infrastructure where Oracle Agile PLM MCAD Connector executes.
- Implement additional monitoring and detection measures for exposed assets.
- Track exceptions and retest remediated assets to ensure the vulnerability is fully addressed.
- Review relevant logs for exposed assets that need extra review.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and vector. The vulnerability is in the CAX Client component of Oracle Agile PLM MCAD Connector. The CVSS 3.1 Base Score is 5.5 (Confidentiality impacts). The CVE record was published on 2026-09-15T20:18:39.887Z and has not been modified since then. The official CVE Program record and NVD detail page offer source-provided CVE metadata and vulnerability assessments.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-83274 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-83274
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-83274 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-83274
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspusep2026.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.