Sceawere
Vulnerability Detail
CVE-2026-61186Updated Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Agile EDM Unauthenticated Access
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.4
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Agile Engineering Data Management
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as unauthorized read access to a subset of Oracle Agile Engineering Data Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as unauthorized read access to a subset of Oracle Agile Engineering Data Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.4",
"pubDate": "2026-07-21T22:18:50.470Z",
"pubdate": "2026-07-21T22:18:50.470Z",
"executiveSummary": "This vulnerability affects Oracle Agile Engineering Data Management version 6.2.1, specifically within the Install component.\nThe flaw allows an unauthenticated, remote attacker to gain unauthorized access to the system over HTTP.\nThe vulnerability is characterized by a high CVSS 3.1 base score of 9.4, reflecting the severity of the potential impact on system security.\nAn attacker can exploit this weakness without any prior authentication, leveraging the network exposure of the application to execute unauthorized actions.\nThe successful exploitation of this vulnerability permits a full compromise of data integrity and availability.\nImpacts include the unauthorized creation, deletion, or modification of critical data, unauthorized read access to sensitive information, and the ability to trigger a complete denial-of-service (DoS) condition via application hangs or crashes.\nThe risk profile is critical due to the lack of required user interaction or privileged credentials, making the product highly susceptible to external exploitation.",
"technicalDetails": "The vulnerability resides within the Install component of Oracle Agile Engineering Data Management version 6.2.1.\nThe root cause is an insecure configuration or lack of access control mechanisms within the installation/management interface, which is reachable via the HTTP protocol.\nBecause the interface does not enforce authentication, an attacker can transmit malicious HTTP requests directly to the targeted component.\nThe attack flow begins with the attacker performing network reconnaissance to identify reachable instances of Oracle Agile Engineering Data Management.\nOnce identified, the attacker crafts specific HTTP payloads designed to bypass or circumvent the application's expected authorization gatekeepers.\nBy sending these requests, the attacker can manipulate internal data structures, leading to unauthorized CRUD (Create, Read, Update, Delete) operations on critical engineering data.\nFurthermore, the attacker can submit malformed or excessively resource-intensive requests that the Install component is unable to process safely, resulting in an unhandled exception or resource exhaustion state.\nThis behavior leads to a crash or a perpetual hang, effectively denying service to legitimate users.\nThe vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H) confirms that the attack requires no special privilege, no user interaction, and can be performed remotely over a network connection.\nPost-exploitation, the attacker maintains full control over the integrity of the data repository, potentially leading to the injection of unauthorized engineering records or the destruction of historical data, while simultaneously disrupting operational continuity through denial-of-service."
}