Sceawere
Vulnerability Detail
CVE-2026-71052UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Agile Engineering Data Management Takeover
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Agile Engineering Data Management
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Web Services Security). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-08-18T21:18:05.063Z",
"pubdate": "2026-08-18T21:18:05.063Z",
"executiveSummary": "A remotely exploitable vulnerability affects the Oracle Agile Engineering Data Management product of Oracle Supply Chain, specifically within the Web Services Security component. The vulnerability impacts version 6.2.1 and allows a low-privileged network attacker to achieve a complete system compromise via HTTP.\nThe security flaw presents significant risk to confidentiality, integrity, and availability, yielding a CVSS 3.1 Base Score of 8.8 with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. Successful exploitation requires network connectivity and low privileges, but does not require user interaction, ultimately enabling the complete takeover of the affected application instance.",
"technicalDetails": "The vulnerability resides within the Web Services Security component of Oracle Agile Engineering Data Management version 6.2.1. The root cause stems from insufficient security controls and validation mechanisms within the handling of web services traffic, exposing the application to unauthorized administrative or systemic operations.\nThe attack flow begins with a network-based adversary establishing an HTTP connection to the vulnerable endpoints exposed by the Web Services Security component. Because the attack vector is network-based (AV:N) and complexity is low (AC:L), an attacker possessing minimal authentication credentials (PR:L) can interact directly with the vulnerable service without requiring user interaction (UI:N).\nUpon establishing communication, the attacker transmits crafted payloads designed to exploit weaknesses in authorization enforcement or input processing within the affected component. The lack of robust privilege boundary enforcement allows the low-privileged user to execute unauthorized actions that exceed their intended scope.\nPost-exploitation impact includes the full takeover of the Oracle Agile Engineering Data Management system. An attacker achieves complete control over confidentiality, integrity, and availability (C:H/I:H/A:H), enabling them to read sensitive engineering data, modify critical records, disrupt operational availability, or leverage the compromised host for further internal network propagation."
}