Junglewise Threat Intelligence

CVE-2026-87260: Oracle Agile Engineering Data Management local data tampering via physical segment

CVE-2026-87260 · Severity: high · CVSS 7.3 · Published 2026-09-15

Technologies: Oracle Agile Engineering Data Management. Vendors: Oracle.

Executive brief

Oracle Agile Engineering Data Management is a product used to manage engineering data and communications within Oracle's supply chain suite. A vulnerability in the Engineering Communication Interface component allows an attacker with physical access to the network segment and low-level privileges to read, modify, or delete sensitive engineering data, potentially impacting data integrity and confidentiality across the system.

Technical details

This vulnerability is a local network-based access control issue in the Engineering Communication Interface component of Oracle Agile Engineering Data Management 6.2.1. The vulnerability requires an attacker to have both adjacent network access (AV:A) to the physical communication segment and low privileges (PR:L), but no user interaction (UI:N). Successful exploitation allows unauthorized creation, deletion, modification, and access to critical data, with high impact on both confidentiality (C:H) and integrity (I:H). No availability impact is noted. The vulnerability is considered easily exploitable despite these preconditions. Patch status or mitigation guidance is not clearly documented in the advisory text.

Affected products

  • Oracle Agile Engineering Data Management 6.2.1

Timeline

  • 2026-09-15: disclosed

References

Related threats