Junglewise Threat Intelligence

CVE-2026-61189: Oracle Agile Engineering Data Management information disclosure in Install component

CVE-2026-61189 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle Agile Engineering Data Management. Vendors: Oracle.

Executive brief

A vulnerability exists in the installation component of Oracle Agile Engineering Data Management, a tool used for managing engineering product data and supply chain processes. An attacker who already has basic access to the server where this software is installed can exploit this flaw to gain unauthorized access to sensitive business data. This could lead to a significant breach of confidentiality and potentially impact other connected systems within the corporate infrastructure.

Technical details

This vulnerability affects the 'Install' component of Oracle Agile Engineering Data Management. It is classified as an information disclosure issue that allows a low-privileged attacker with local logon access to the underlying infrastructure to compromise the application. The exploit is described as 'easily exploitable' and involves a scope change (S:C), meaning the impact can extend beyond the immediate application to other parts of the environment. Successful exploitation results in high confidentiality impacts, potentially granting complete access to all data accessible by the application. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Agile Engineering Data Management 6.2.1

Timeline

  • 2026-07-21: advisory: Published as part of the Oracle Critical Patch Update

References

Related threats