Description
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access and Modification
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the Engineering Communication Interface component of Oracle Agile Engineering Data Management 6.2.1. It allows an unauthenticated attacker who has access to the physical communication segment attached to the hardware where the product runs to compromise the system. Successful exploitation can expose critical data (high confidentiality impact) and permit unauthorized read, insert, update, or delete operations on accessible data (low integrity impact). The weakness involves improper access control that lets attackers bypass authentication checks and perform data operations that are not permitted for unauthenticated users.

Affected Systems

Oracle Agile Engineering Data Management version 6.2.1, part of Oracle Supply Chain Management, specifically the Engineering Communication Interface component.

Risk and Exploitability

The CVSS 3.1 base score of 7.1 indicates a moderate to high severity vulnerability. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and it is not catalogued in CISA's KEV. However, because the attack requires physical or network segment access to the hardware's communication interface, the threat is limited to environments where an attacker can reach that segment. The serious confidentiality impact warrants treating it as a higher risk for deployments exposed to physical or segment‑level access.

Generated by OpenCVE AI on September 18, 2026 at 16:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle's official patch for Agile Engineering Data Management 6.2.1 that addresses this vulnerability.
  • Restrict physical and segment-level access to the communication interface, ensuring only authorized personnel can connect to or monitor that channel.
  • Implement monitoring and logging on the communication interface and enforce least privilege policies to detect and prevent unauthorized data operations.

Generated by OpenCVE AI on September 18, 2026 at 16:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access and Data Modification via Physical Communication Channel in Oracle Agile Engineering Data Management 6.2.1

Wed, 16 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access and Data Modification via Physical Communication Channel in Oracle Agile Engineering Data Management 6.2.1
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle agile Engineering Data Management
CPEs cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Engineering Data Management
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Agile Engineering Data Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:11:18.277Z

Reserved: 2026-09-08T21:49:12.407Z

Link: CVE-2026-87262

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:19:14.930

Modified: 2026-09-17T16:18:21.240

Link: CVE-2026-87262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T16:30:10Z

Weaknesses