Junglewise Threat Intelligence

CVE-2026-70709: Oracle Agile Engineering Data Management data manipulation in Engineering Communication Interface

CVE-2026-70709 · Severity: medium · CVSS 4.8 · Published 2026-08-18

Technologies: Oracle Agile Engineering Data Management. Vendors: Oracle.

Executive brief

Oracle Agile Engineering Data Management is a supply-chain planning tool that manages engineering project data. An unauthenticated network attacker can exploit a flaw in the Engineering Communication Interface component to read, modify, and delete sensitive project data, compromising data integrity and exposing confidential engineering information.

Technical details

This is a logic or authorization bypass vulnerability in the Engineering Communication Interface component of Oracle Agile Engineering Data Management 6.2.1. The flaw allows unauthenticated attackers with network access via HTTP to bypass access controls and manipulate data. Attack preconditions are minimal—no authentication or user interaction is required, though exploitation is rated as difficult (high attack complexity). A successful exploit grants unauthorized read, create, update, and delete access to a subset of the product's data assets, affecting both confidentiality and integrity. A patch or update is likely available through Oracle's regular security update channels.

Affected products

  • Oracle Agile Engineering Data Management 6.2.1

Timeline

  • 2026-08-18: disclosed

References

Related threats