A critical, easily exploitable vulnerability in Oracle Agile Engineering Data Management lets unauthenticated network attackers compromise the product, carrying a CVSS 3.1 base score of 9.4.
What Is It
CVE-2026-61186 is a critical vulnerability in the Oracle Agile Engineering Data Management product, part of Oracle Supply Chain (component: Install). Oracle rates it CVSS 3.1 base score 9.4 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H. The flaw is described as easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the product; no privileges or user interaction required.
Why It Matters
Successful exploitation can result in unauthorized creation, deletion, or modification of critical data (or all data accessible to the product), unauthorized read access to a subset of accessible data, and the ability to cause a hang or frequently repeatable crash; a complete denial of service. The combination of network attack vector, low complexity, no authentication, and high integrity and availability impact makes this a serious risk for exposed deployments.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Agile Engineering Data Management (Oracle Supply Chain)
- Component: Install
- Affected version: 6.2.1
Patch Status
The vulnerability is addressed in Oracle's July 2026 Critical Patch Update. Administrators should consult the Oracle Critical Patch Update advisory (July 2026) and apply the associated fixes. This CVE was published on 2026-07-21 with an NVD status of "Received." No CISA KEV entry was supplied, so there is no confirmation of active exploitation in the provided source material.