Description
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Web Services Security). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Web Services Security component of Oracle Agile Engineering Data Management allows an unauthenticated attacker to access the system via HTTP and take complete control, exposing confidential data, corrupting integrity, and disrupting availability. The weakness is identified as CWE-284, Improper Access Control, and enables a remote attacker to abuse the application without credentials.

Affected Systems

Oracle Agile Engineering Data Management version 6.2.1 is affected by this vulnerability.

Risk and Exploitability

The CVSS base score of 8.1 indicates severity, and the attack vector is inferred to be remote over HTTP with no authentication required. The EPSS score of < 1% signals a very low probability of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the potential for full system takeover warrants close attention if the flaw becomes publicly known.

Generated by OpenCVE AI on August 20, 2026 at 19:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch for Agile Engineering Data Management 6.2.1 as released on the Oracle Security Alerts page for 2026.
  • Restrict inbound HTTP access to the Agile Engineering Data Management instance using firewall rules or VPN tunnels to limit exposure to potential attackers.
  • Ensure that Web Services Security interfaces are protected by strict authentication and access controls to prevent unauthenticated use.

Generated by OpenCVE AI on August 20, 2026 at 19:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*

Thu, 20 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Leads to Full System Compromise in Oracle Agile Engineering Data Management

Wed, 19 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Leads to Full Compromise of Oracle Agile Engineering Data Management
Weaknesses CWE-287

Wed, 19 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Leads to Full Compromise of Oracle Agile Engineering Data Management
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Web Services Security). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle agile Engineering Data Management
CPEs cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Engineering Data Management
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Agile Engineering Data Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:04:41.674Z

Reserved: 2026-08-04T22:06:34.614Z

Link: CVE-2026-71053

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:05.173

Modified: 2026-08-24T15:51:48.870

Link: CVE-2026-71053

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T19:30:05Z

Weaknesses