Executive brief
Oracle Agile Engineering Data Management is a product used to manage engineering data and documents in supply chain environments. A vulnerability in the Engineering Communication Interface component allows a low-privileged user with local access to read sensitive data, modify records, or delete information from the system, with potential impact extending to other connected applications.
Technical details
The vulnerability is a local privilege escalation or data access control flaw in the Engineering Communication Interface component of Oracle Agile Engineering Data Management version 6.2.1. An attacker with low privilege logon credentials and local access to the infrastructure can exploit this issue without user interaction required. Successful exploitation grants unauthorized read access to critical data, write/delete access to some data, and may impact additional products due to scope change. The CVSS 3.1 score of 7.3 reflects high confidentiality and partial integrity impact with local attack vector. Patch information from Oracle has not been verified due to technical issues with the advisory page.
Affected products
- Oracle Agile Engineering Data Management 6.2.1
Timeline
- 2026-09-15: disclosed
- 2026-09-15: advisory