Junglewise Threat Intelligence

CVE-2026-61192: Oracle Agile Engineering Data Management denial of service in Install component

CVE-2026-61192 · Severity: medium · CVSS 5.3 · Published 2026-07-21

Technologies: Oracle Agile Engineering Data Management. Vendors: Oracle.

Executive brief

Oracle Agile Engineering Data Management, a tool used for managing product lifecycle and engineering data, contains a vulnerability in its installation component. A low-privileged user could exploit this flaw to cause the system to hang or crash repeatedly. This would result in a denial-of-service, preventing legitimate users from accessing critical engineering data and disrupting supply chain operations.

Technical details

A vulnerability in the 'Install' component of Oracle Agile Engineering Data Management (version 6.2.1) allows for a denial-of-service (DoS) attack. The flaw is accessible via the network over HTTP, though it requires the attacker to have low-level authenticated privileges. The attack is characterized as difficult to exploit (Attack Complexity: High), but a successful exploit allows an attacker to cause a frequently repeatable crash or a complete system hang. This impacts the availability of the service without affecting data confidentiality or integrity. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Agile Engineering Data Management 6.2.1

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats