Junglewise Threat Intelligence

CVE-2026-61191: Oracle Agile Engineering Data Management data manipulation in Document Management

CVE-2026-61191 · Severity: medium · CVSS 4.4 · Published 2026-07-21

Technologies: Oracle Agile Engineering Data Management. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Agile Engineering Data Management, a tool used for managing technical product data and documentation. A user with low-level access to the underlying server can exploit this flaw to modify or delete sensitive engineering data. Additionally, an attacker could disrupt operations by causing a partial service outage, potentially delaying engineering workflows.

Technical details

A vulnerability in the Document Management component of Oracle Agile Engineering Data Management (version 6.2.1) allows for unauthorized data manipulation and service disruption. The flaw is categorized as easily exploitable but requires the attacker to have local logon access to the infrastructure where the software executes. Successful exploitation enables a low-privileged user to perform unauthorized update, insert, or delete operations on a subset of accessible data. It also allows the attacker to trigger a partial denial of service (DoS) affecting the application's availability. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Agile Engineering Data Management 6.2.1

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed

References

Related threats