Junglewise Threat Intelligence

CVE-2026-87259: Oracle Agile Engineering Data Management privilege escalation in Engineering Communication Interface

CVE-2026-87259 · Severity: high · CVSS 8.4 · Published 2026-09-15

Technologies: Oracle Agile Engineering Data Management. Vendors: Oracle.

Executive brief

Oracle Agile Engineering Data Management is an enterprise platform for managing engineering project data and collaboration. A vulnerability in the Engineering Communication Interface allows a low-privileged user with local access to gain elevated permissions and access, modify, or delete critical project data. Successful exploitation can compromise sensitive engineering data and potentially impact other connected systems in the supply chain.

Technical details

A privilege escalation vulnerability exists in the Engineering Communication Interface component of Oracle Agile Engineering Data Management 6.2.1. The vulnerability is easily exploitable and requires only local logon access and low privileges to trigger; no user interaction is needed. An authenticated attacker can leverage this flaw to escalate privileges and gain unauthorized access to create, modify, or delete critical data, as well as read all accessible data within the application. The scope is marked as changed, indicating potential impact to other Oracle products. Patches or updates should be obtained from Oracle's security advisories.

Affected products

  • Oracle Agile Engineering Data Management 6.2.1

Timeline

  • 2026-09-15: disclosed

References

Related threats