Junglewise Threat Intelligence

CVE-2026-61194: Oracle Agile Engineering Data Management denial of service in Core component

CVE-2026-61194 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle Agile Engineering Data Management. Vendors: Oracle.

Executive brief

Oracle Agile Engineering Data Management, a tool used to manage product design and engineering data throughout the supply chain, is vulnerable to a denial-of-service attack. An attacker with basic network access and low-level user credentials can cause the system to hang or crash repeatedly. This could disrupt engineering operations and prevent staff from accessing critical design data.

Technical details

A vulnerability in the Core component of Oracle Agile Engineering Data Management version 6.2.1 allows for a denial-of-service (DoS) attack. The flaw is easily exploitable by a low-privileged attacker with network access via TCP. Successful exploitation allows the attacker to cause a hang or a frequently repeatable crash of the application, impacting system availability. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Agile Engineering Data Management 6.2.1

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats