Junglewise Threat Intelligence

CVE-2026-70697: Oracle Agile Engineering Data Management privilege escalation in Engineering Communication Interface

CVE-2026-70697 · Severity: high · CVSS 7 · Published 2026-08-18

Technologies: Oracle Agile Engineering Data Management. Vendors: Oracle.

Executive brief

Oracle Agile Engineering Data Management is a product suite used by enterprises to manage engineering data and supply chain processes. A vulnerability in the Engineering Communication Interface component allows a low-privileged local user with system access to gain complete control over the application, compromising confidentiality, integrity, and availability of sensitive engineering and supply chain data.

Technical details

This is a local privilege escalation vulnerability in the Engineering Communication Interface component of Oracle Agile Engineering Data Management 6.2.1. The vulnerability is difficult to exploit and requires an authenticated attacker with low-privilege local access to the infrastructure running the product. Successful exploitation results in complete compromise of the affected application with full confidentiality, integrity, and availability impact. The CVSS 3.1 score of 7.0 reflects the high impact of successful exploitation, though the requirement for local access and elevated exploitation difficulty limit the attack surface.

Affected products

  • Oracle Agile Engineering Data Management 6.2.1

Timeline

  • 2026-08-18: disclosed

References

Related threats