Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-61186: Oracle Agile Engineering Data Management 6.2.1 allows unauthorized data access

CVE-2026-61186 · published 2 months ago
Summary

An attacker can access sensitive data or cause Oracle Agile Engineering Data Management to crash. This affects version 6.2.1 of Oracle Agile Engineering Data Management. You should update to a fixed version to prevent unauthorized access or crashes.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
oracle corporation oracle agile engineering data management 6.2.1
oracle agile_engineering_data_management 6.2.1.0
cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*
Original advisory text
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerabilit...
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as unauthorized read access to a subset of Oracle Agile Engineering Data Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H).
Severity
9.4 Critical
CVSS 3.1: 9.4 (MITRE)
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
CWE-306Missing Authentication for Critical Function
CWE-400Uncontrolled Resource Consumption
CWE-732Incorrect Permission Assignment for Critical Resource
Timeline
Published21 Jul 2026
Updated27 Sep 2026
First seen23 Jul 2026
Sources
CVE-2026-61186 · MITRE
Track software like this
Free during beta