CNVD-2026-34480

Vulnerability from cnvd - Published: 2026-08-31
VLAI
Title
Oracle Agile PLM MCAD Connector未经授权访问漏洞(CNVD-2026-34480)
Description
Oracle Agile PLM MCAD Connector是甲骨文(Oracle)供应链产品线中用于在‌AgilePLM系统‌与主流‌MCAD(机械计算机辅助设计)软件‌之间实现双向数据交换与流程集成的专用连接器组件,属闭源商业软件。 Oracle Agile PLM MCAD Connector存在未经授权访问漏洞,该漏洞源于CAX Client组件对物理通信网段访问请求的权限校验存在缺陷。攻击者可利用该漏洞接入同一物理通信网段后读取关键数据或全部可访问数据。
Severity
中
Patch Name
Oracle Agile PLM MCAD Connector未经授权访问漏洞(CNVD-2026-34480)的补丁
Patch Description
Oracle Agile PLM MCAD Connector是甲骨文(Oracle)供应链产品线中用于在‌AgilePLM系统‌与主流‌MCAD(机械计算机辅助设计)软件‌之间实现双向数据交换与流程集成的专用连接器组件,属闭源商业软件。 Oracle Agile PLM MCAD Connector存在未经授权访问漏洞,该漏洞源于CAX Client组件对物理通信网段访问请求的权限校验存在缺陷。攻击者可利用该漏洞接入同一物理通信网段后读取关键数据或全部可访问数据。目前,供应商发布了安全公告及相关补丁信息,修复了此漏洞。
Formal description

目前厂商已发布升级程序修复该安全问题,详情见厂商官网: https://www.oracle.com/security-alerts/cspuaug2026.html

Reference
https://nvd.nist.gov/vuln/detail/CVE-2026-71077
Impacted products
Name
Oracle Agile PLM MCAD Connector 3.6
Show details on source website

{
  "cves": {
    "cve": {
      "cveNumber": "CVE-2026-71077",
      "cveUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-71077"
    }
  },
  "description": "Oracle Agile PLM MCAD Connector\u662f\u7532\u9aa8\u6587\uff08Oracle\uff09\u4f9b\u5e94\u94fe\u4ea7\u54c1\u7ebf\u4e2d\u7528\u4e8e\u5728\u200cAgilePLM\u7cfb\u7edf\u200c\u4e0e\u4e3b\u6d41\u200cMCAD\uff08\u673a\u68b0\u8ba1\u7b97\u673a\u8f85\u52a9\u8bbe\u8ba1\uff09\u8f6f\u4ef6\u200c\u4e4b\u95f4\u5b9e\u73b0\u53cc\u5411\u6570\u636e\u4ea4\u6362\u4e0e\u6d41\u7a0b\u96c6\u6210\u7684\u4e13\u7528\u8fde\u63a5\u5668\u7ec4\u4ef6\uff0c\u5c5e\u95ed\u6e90\u5546\u4e1a\u8f6f\u4ef6\u3002\n\nOracle Agile PLM MCAD Connector\u5b58\u5728\u672a\u7ecf\u6388\u6743\u8bbf\u95ee\u6f0f\u6d1e\uff0c\u8be5\u6f0f\u6d1e\u6e90\u4e8eCAX Client\u7ec4\u4ef6\u5bf9\u7269\u7406\u901a\u4fe1\u7f51\u6bb5\u8bbf\u95ee\u8bf7\u6c42\u7684\u6743\u9650\u6821\u9a8c\u5b58\u5728\u7f3a\u9677\u3002\u653b\u51fb\u8005\u53ef\u5229\u7528\u8be5\u6f0f\u6d1e\u63a5\u5165\u540c\u4e00\u7269\u7406\u901a\u4fe1\u7f51\u6bb5\u540e\u8bfb\u53d6\u5173\u952e\u6570\u636e\u6216\u5168\u90e8\u53ef\u8bbf\u95ee\u6570\u636e\u3002",
  "formalWay": "\u76ee\u524d\u5382\u5546\u5df2\u53d1\u5e03\u5347\u7ea7\u7a0b\u5e8f\u4fee\u590d\u8be5\u5b89\u5168\u95ee\u9898\uff0c\u8be6\u60c5\u89c1\u5382\u5546\u5b98\u7f51:\r\nhttps://www.oracle.com/security-alerts/cspuaug2026.html",
  "isEvent": "\u901a\u7528\u8f6f\u786c\u4ef6\u6f0f\u6d1e",
  "number": "CNVD-2026-34480",
  "openTime": "2026-08-31",
  "patchDescription": "Oracle Agile PLM MCAD Connector\u662f\u7532\u9aa8\u6587\uff08Oracle\uff09\u4f9b\u5e94\u94fe\u4ea7\u54c1\u7ebf\u4e2d\u7528\u4e8e\u5728\u200cAgilePLM\u7cfb\u7edf\u200c\u4e0e\u4e3b\u6d41\u200cMCAD\uff08\u673a\u68b0\u8ba1\u7b97\u673a\u8f85\u52a9\u8bbe\u8ba1\uff09\u8f6f\u4ef6\u200c\u4e4b\u95f4\u5b9e\u73b0\u53cc\u5411\u6570\u636e\u4ea4\u6362\u4e0e\u6d41\u7a0b\u96c6\u6210\u7684\u4e13\u7528\u8fde\u63a5\u5668\u7ec4\u4ef6\uff0c\u5c5e\u95ed\u6e90\u5546\u4e1a\u8f6f\u4ef6\u3002\r\n\r\nOracle Agile PLM MCAD Connector\u5b58\u5728\u672a\u7ecf\u6388\u6743\u8bbf\u95ee\u6f0f\u6d1e\uff0c\u8be5\u6f0f\u6d1e\u6e90\u4e8eCAX Client\u7ec4\u4ef6\u5bf9\u7269\u7406\u901a\u4fe1\u7f51\u6bb5\u8bbf\u95ee\u8bf7\u6c42\u7684\u6743\u9650\u6821\u9a8c\u5b58\u5728\u7f3a\u9677\u3002\u653b\u51fb\u8005\u53ef\u5229\u7528\u8be5\u6f0f\u6d1e\u63a5\u5165\u540c\u4e00\u7269\u7406\u901a\u4fe1\u7f51\u6bb5\u540e\u8bfb\u53d6\u5173\u952e\u6570\u636e\u6216\u5168\u90e8\u53ef\u8bbf\u95ee\u6570\u636e\u3002\u76ee\u524d\uff0c\u4f9b\u5e94\u5546\u53d1\u5e03\u4e86\u5b89\u5168\u516c\u544a\u53ca\u76f8\u5173\u8865\u4e01\u4fe1\u606f\uff0c\u4fee\u590d\u4e86\u6b64\u6f0f\u6d1e\u3002",
  "patchName": "Oracle Agile PLM MCAD Connector\u672a\u7ecf\u6388\u6743\u8bbf\u95ee\u6f0f\u6d1e\uff08CNVD-2026-34480\uff09\u7684\u8865\u4e01",
  "products": {
    "product": "Oracle Agile PLM MCAD Connector 3.6"
  },
  "referenceLink": "https://nvd.nist.gov/vuln/detail/CVE-2026-71077",
  "serverity": "\u4e2d",
  "submitTime": "2026-08-25",
  "title": "Oracle Agile PLM MCAD Connector\u672a\u7ecf\u6388\u6743\u8bbf\u95ee\u6f0f\u6d1e\uff08CNVD-2026-34480\uff09"
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…