SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61186 2026-07-21

CVE-2026-61186: Critical Unauthenticated Flaw in Oracle Agile Engineering Data Management

"A critical, easily exploitable vulnerability in Oracle Agile Engineering Data Management lets unauthenticated network attackers compromise the product, carrying a CVSS 3.1 base score of 9.4."

A critical, easily exploitable vulnerability in Oracle Agile Engineering Data Management lets unauthenticated network attackers compromise the product, carrying a CVSS 3.1 base score of 9.4.

What Is It

CVE-2026-61186 is a critical vulnerability in the Oracle Agile Engineering Data Management product, part of Oracle Supply Chain (component: Install). Oracle rates it CVSS 3.1 base score 9.4 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H. The flaw is described as easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the product; no privileges or user interaction required.

Why It Matters

Successful exploitation can result in unauthorized creation, deletion, or modification of critical data (or all data accessible to the product), unauthorized read access to a subset of accessible data, and the ability to cause a hang or frequently repeatable crash; a complete denial of service. The combination of network attack vector, low complexity, no authentication, and high integrity and availability impact makes this a serious risk for exposed deployments.

What's Vulnerable

Patch Status

The vulnerability is addressed in Oracle's July 2026 Critical Patch Update. Administrators should consult the Oracle Critical Patch Update advisory (July 2026) and apply the associated fixes. This CVE was published on 2026-07-21 with an NVD status of "Received." No CISA KEV entry was supplied, so there is no confirmation of active exploitation in the provided source material.

Sources