Description
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access and Modification
Action: Patch Immediately
AI Analysis

Impact

The vulnerability enables a low‑privileged attacker who has access to the physical communication segment attached to the hardware running Oracle Agile Engineering Data Management to create, delete, modify, or otherwise gain unauthorized access to all critical data stored in the system. The impact includes full confidentiality and integrity compromise of available data, with no availability impact reported.

Affected Systems

Oracle Agile Engineering Data Management version 6.2.1 is the only affected product. The vulnerability is tied to the Engineering Communication Interface component of this product, and the attack requires physical proximity or access to the communication network segment.

Risk and Exploitability

The CVSS 3.1 base score of 7.3 indicates a high severity, and the vector of AV:A/AC:L/PR:L/UI:N/S:U shows the attack is local, requires low effort, and does not need user interaction. The EPSS score of less than 1% suggests exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, should the flaw be leveraged, the consequences would be severe, particularly given the breadth of data that could be accessed or altered.

Generated by OpenCVE AI on September 18, 2026 at 16:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check Oracle’s available security advisories for updates addressing the Engineering Communication Interface component and apply any patches as soon as they are released.
  • Physically restrict or lock the hardware devices that connect to the Oracle Agile Engineering Data Management communication segment to prevent low‑privileged attackers from obtaining physical access.
  • Disable or limit the use of the Engineering Communication Interface when it is not required and monitor system logs for any unauthorized access attempts.

Generated by OpenCVE AI on September 18, 2026 at 16:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Local Access Enables Unauthorized Data Modification in Oracle Agile Engineering Data Management

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Local Access Enables Unauthorized Data Modification in Oracle Agile Engineering Data Management
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle agile Engineering Data Management
CPEs cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Engineering Data Management
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Agile Engineering Data Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:11:38.422Z

Reserved: 2026-09-08T21:49:12.407Z

Link: CVE-2026-87260

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:09.267Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:19:14.713

Modified: 2026-09-17T16:18:20.953

Link: CVE-2026-87260

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T17:00:13Z

Weaknesses