Description
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authentication bypass exists in the Engineering Communication Interface that allows an attacker who can physically connect to the communication segment attached to the Oracle Agile Engineering Data Management hardware to send arbitrary commands without authentication. This is a CWE-284 Incorrect Access Control flaw. The flaw enables the attacker to execute any operation the system supports, effectively taking control of the application and the data it manages, which results in complete compromise of confidentiality, integrity and availability.

Affected Systems

The vulnerability affects Oracle Agile Engineering Data Management version 6.2.1, part of Oracle Supply Chain Management. Only this specific version is listed as vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 indicates a moderate‑to‑high severity. EPSS score of < 1% indicates a very low probability of exploitation and the flaw is not in the CISA KEV catalog. The attack vector (AV:A) shows that an attacker must act from an adjacent physical segment, requiring high effort and no credentials. Once physical access is achieved, the attacker can fully take over the system, presenting a high risk especially for environments that expose the engineering communication interface. The lack of an immediate patch elevates the threat, though the necessity of physical proximity mitigates remote risk.

Generated by OpenCVE AI on August 24, 2026 at 22:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch for Oracle Agile Engineering Data Management 6.2.1 as soon as it becomes available
  • Restrict and monitor physical access to the communication segment, ensuring only authorized personnel can connect to the hardware interface
  • Disable the Engineering Communication Interface if it is not required, or enforce strong authentication and encryption on it
  • Deploy host‑based monitoring and logging to detect and alert on unauthorized traffic or commands on the interface
  • Segregate the Oracle Agile environment from other production networks through physical or logical separation

Generated by OpenCVE AI on August 24, 2026 at 22:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Physical Access Exploit Enables Full System Compromise in Oracle Agile Engineering Data Management 6.2.1

Mon, 24 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*

Wed, 19 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Physical Access Exploit Enables Full System Compromise in Oracle Agile Engineering Data Management 6.2.1
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle agile Engineering Data Management
CPEs cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Engineering Data Management
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Agile Engineering Data Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T03:57:07.940Z

Reserved: 2026-08-04T22:06:34.590Z

Link: CVE-2026-70691

cve-icon Vulnrichment

Updated: 2026-08-24T19:50:38.200Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:21.110

Modified: 2026-08-25T04:18:16.883

Link: CVE-2026-70691

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:45:03Z

Weaknesses