Junglewise Threat Intelligence

CVE-2026-61187: Oracle Agile Engineering Data Management partial DoS in Install component

CVE-2026-61187 · Severity: low · CVSS 2.8 · Published 2026-07-21

Technologies: Oracle Agile Engineering Data Management. Vendors: Oracle.

Executive brief

A vulnerability exists in the installation component of Oracle Agile Engineering Data Management, a tool used for managing engineering product data and supply chain workflows. A low-privileged user with access to the underlying system could potentially cause a partial service outage, disrupting business operations. Exploiting this issue requires a legitimate user to perform a specific action, such as clicking a link or opening a file provided by the attacker.

Technical details

A vulnerability in the 'Install' component of Oracle Agile Engineering Data Management version 6.2.1 allows for a partial denial of service (DoS). The flaw is easily exploitable by a low-privileged attacker who has local logon access to the infrastructure where the software is running. Successful exploitation requires human interaction from a user other than the attacker (UI:R). The impact is limited to availability, with no reported impact on data confidentiality or integrity. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Agile Engineering Data Management 6.2.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD record published

References

Related threats