Junglewise Threat Intelligence

CVE-2026-87262: Oracle Agile Engineering Data Management physical network access compromise in Engineering Communication Interface

CVE-2026-87262 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle Agile Engineering Data Management. Vendors: Oracle.

Executive brief

Oracle Agile Engineering Data Management is a supply chain product used to manage engineering data and collaboration. An unauthenticated attacker with physical access to the network segment where the system runs can exploit a vulnerability in the Engineering Communication Interface to read, modify, or delete sensitive engineering data without authorization.

Technical details

The vulnerability is an unauthenticated remote code execution or unauthorized access issue in the Engineering Communication Interface component of Oracle Agile Engineering Data Management version 6.2.1. The vulnerability requires physical network access to the communication segment attached to the hardware running the product, meaning an attacker must be on the same network segment or have compromised an adjacent system. Successful exploitation allows an attacker to gain unauthorized access to all data managed by the application and perform unauthorized modifications or deletions. The vulnerability has a CVSS 3.1 score of 7.1 with high confidentiality and partial integrity impact.

Affected products

  • Oracle Agile Engineering Data Management 6.2.1

Timeline

  • 2026-09-15: disclosed

References

Related threats