Junglewise Threat Intelligence

CVE-2026-61186: Oracle Agile Engineering Data Management compromise in Install component

CVE-2026-61186 · Severity: critical · CVSS 9.4 · Published 2026-07-21

Technologies: Oracle Agile Engineering Data Management. Vendors: Oracle.

Executive brief

Oracle Agile Engineering Data Management, a tool used to manage product lifecycle and engineering data, contains a critical security flaw in its installation component. An unauthorized attacker can exploit this over the network to gain full control over the system's data, allowing them to delete, modify, or view sensitive information. Additionally, the exploit can be used to crash the service, leading to a complete disruption of engineering operations.

Technical details

A vulnerability exists in the Install component of Oracle Agile Engineering Data Management version 6.2.1. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows for unauthorized creation, deletion, or modification of all accessible data, as well as unauthorized read access to a subset of data. Furthermore, the attacker can cause a hang or a frequently repeatable crash, resulting in a complete denial of service (DoS). The vulnerability has a CVSS 3.1 base score of 9.4, reflecting high impacts on integrity and availability.

Affected products

  • Oracle Agile Engineering Data Management 6.2.1

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle in the July 2026 Critical Patch Update.

References

Related threats