Junglewise Threat Intelligence

CVE-2026-70712: Oracle Agile Engineering Data Management privilege escalation in Install component

CVE-2026-70712 · Severity: medium · CVSS 6.4 · Published 2026-08-18

Technologies: Oracle Agile Engineering Data Management. Vendors: Oracle.

Executive brief

Oracle Agile Engineering Data Management is used for product lifecycle and engineering data organization within supply chain operations. A vulnerability in the installation component allows a privileged attacker with local system access to fully compromise the system, potentially taking control of all data and operations managed by this application.

Technical details

This is a local privilege escalation vulnerability in the Install component of Oracle Agile Engineering Data Management version 6.2.1. The vulnerability requires high privilege and local system logon access, making it difficult to exploit. Successful exploitation allows an attacker with existing infrastructure access to gain complete control over the Agile Engineering Data Management system, affecting confidentiality, integrity, and availability. The exact root cause and patch status are not fully documented in available sources.

Affected products

  • Oracle Agile Engineering Data Management 6.2.1

Timeline

  • 2026-08-18: disclosed

References

Related threats