Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-61189

CVE-2026-61189: Oracle Agile EDM Information Disclosure

CVE-2026-61189 is an information disclosure vulnerability in Oracle Agile Engineering Data Management that allows low-privileged attackers to access critical data. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-61189 Overview

CVE-2026-61189 affects the Install component of Oracle Agile Engineering Data Management, part of the Oracle Supply Chain product family. The flaw exists in version 6.2.1 and allows a low-privileged attacker with local logon access to compromise the application. Exploitation requires no user interaction and involves a scope change, meaning attacks can impact resources beyond the vulnerable component. Successful exploitation grants unauthorized access to critical data or complete read access to all data accessible by Oracle Agile Engineering Data Management. The vulnerability affects confidentiality only, with no direct impact on integrity or availability.

Critical Impact

A local authenticated attacker can obtain unauthorized read access to all data managed by Oracle Agile Engineering Data Management, with scope-changing impact on adjacent products.

Affected Products

  • Oracle Agile Engineering Data Management 6.2.1
  • Oracle Supply Chain product family (Install component)
  • Deployments where the Oracle Agile EDM infrastructure is co-located with other Oracle products

Discovery Timeline

Technical Details for CVE-2026-61189

Vulnerability Analysis

The vulnerability resides in the Install component of Oracle Agile Engineering Data Management. An attacker with valid low-privilege credentials on the infrastructure hosting the application can leverage the flaw to read sensitive data across trust boundaries. The CVSS vector indicates a scope change, meaning the vulnerable component and the impacted component differ. This scope change is the defining characteristic of the issue: exploitation from within the Agile EDM installation context reaches data that should be isolated from the attacker's authorization scope.

Because the attack vector is local and requires authentication, the flaw is most relevant to insider threat scenarios and post-compromise lateral movement. An adversary who has already established a foothold on the host through phishing, credential theft, or another initial-access technique can escalate their data access without needing additional privileges.

Root Cause

Oracle has not published detailed root cause information beyond the Critical Patch Update advisory. The flaw is categorized under the Install component, which typically covers installation artifacts, configuration files, and setup scripts. Common root causes in this class include weak file permissions on installation directories, insecure handling of configuration secrets, or missing access controls on installer-generated resources that expose data outside the intended trust boundary.

Attack Vector

Exploitation requires local logon access to the server running Oracle Agile Engineering Data Management. The attacker must hold low-level privileges, such as those of a standard application user or service account. No user interaction is required, and the attack complexity is low. Once triggered, the attacker gains read access to data managed by Agile EDM and potentially data owned by adjacent Oracle products sharing the infrastructure.

No public proof-of-concept exploit is available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score indicates a low current probability of exploitation in the wild.

Detection Methods for CVE-2026-61189

Indicators of Compromise

  • Unexpected read access to Oracle Agile EDM configuration files, installer directories, or database export files by non-administrative accounts
  • Anomalous process activity from low-privileged user contexts accessing Agile EDM binaries or data stores
  • Local logon events from service or application accounts that normally do not perform interactive logons

Detection Strategies

  • Audit file system access on directories owned by the Agile EDM installation, particularly configuration and data paths
  • Correlate local authentication events with subsequent access to Oracle product data stores across the same host
  • Alert on cross-product data access patterns that indicate scope-crossing behavior consistent with the CVSS scope change

Monitoring Recommendations

  • Enable operating system auditing for file reads on Oracle Agile EDM installation directories and configuration files
  • Forward host telemetry, authentication logs, and file access events to a centralized data lake for correlation
  • Baseline normal access patterns for Agile EDM service accounts and alert on deviations

How to Mitigate CVE-2026-61189

Immediate Actions Required

  • Apply the fixes distributed in the Oracle Critical Patch Update July 2026 to all Oracle Agile Engineering Data Management 6.2.1 deployments
  • Inventory hosts running Agile EDM and identify shared infrastructure with other Oracle products that could be impacted by the scope change
  • Review and tighten local account access on Agile EDM servers, removing unnecessary interactive logon rights

Patch Information

Oracle addressed CVE-2026-61189 in the Oracle Critical Patch Update released in July 2026. Administrators should download the patch from My Oracle Support and apply it following Oracle's documented upgrade procedure for Agile Engineering Data Management 6.2.1. Consult the Oracle Security Alert July 2026 advisory for the full list of components and patch identifiers.

Workarounds

  • Restrict local logon to the Agile EDM server to a minimal set of trusted administrators
  • Enforce least-privilege on all service accounts that interact with the Agile EDM installation directory
  • Segment the Agile EDM host from other Oracle product deployments to limit the impact of the scope change until patches are applied

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.