Junglewise Threat Intelligence

CVE-2026-70693: Oracle Agile Engineering Data Management privilege escalation in Engineering Communication Interface

CVE-2026-70693 · Severity: medium · CVSS 6.3 · Published 2026-08-18

Technologies: Oracle Agile Engineering Data Management. Vendors: Oracle.

Executive brief

Oracle Agile Engineering Data Management is a product used to manage engineering data and communications within supply chain operations. A vulnerability in the Engineering Communication Interface component allows a high-privileged attacker with local access to take over the system if they can trick another authorized user into performing an action, potentially compromising the confidentiality, integrity, and availability of critical engineering data and communications.

Technical details

This is a privilege escalation vulnerability in the Engineering Communication Interface component of Oracle Agile Engineering Data Management version 6.2.1. The vulnerability requires local attack vector (AV:L), is difficult to exploit (AC:H), and requires both high privileges (PR:H) and user interaction from a secondary party (UI:R). An attacker with high privileges and local system access can exploit this to achieve complete compromise of the affected system including confidentiality, integrity, and availability impacts. Patch status and workarounds are not specified in the available advisory information.

Affected products

  • Oracle Agile Engineering Data Management 6.2.1

Timeline

  • 2026-08-18: disclosed

References

Related threats