Junglewise Threat Intelligence

CVE-2026-61190: Oracle Agile Engineering Data Management security bypass in Install component

CVE-2026-61190 · Severity: medium · CVSS 6.4 · Published 2026-07-21

Technologies: Oracle Agile Engineering Data Management. Vendors: Oracle.

Executive brief

Oracle Agile Engineering Data Management, a tool used for managing complex engineering product data, contains a security vulnerability in its installation component. A low-privileged attacker could potentially gain unauthorized access to or modify critical business data. Exploiting this flaw is difficult as it requires a legitimate user to interact with a malicious link or request while the attacker is connected to the network.

Technical details

This vulnerability affects the Install component of Oracle Agile Engineering Data Management version 6.2.1. It is classified as a medium-severity issue with a CVSS score of 6.4, primarily impacting confidentiality and integrity. An attacker with low privileges can exploit this over HTTP, though the attack complexity is high and requires interaction from a victim (User Interaction: Required). Successful exploitation allows the attacker to create, delete, or modify critical data, or gain full access to all data accessible by the application. The vulnerability was disclosed as part of the Oracle Critical Patch Update (CPU) for July 2026.

Affected products

  • Oracle Agile Engineering Data Management 6.2.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update and NVD publication.

References

Related threats