CVE-2026-61190 Overview
CVE-2026-61190 affects the Install component of Oracle Agile Engineering Data Management, part of the Oracle Supply Chain product family. The supported version affected is 6.2.1. A low-privileged attacker with network access via HTTP can compromise the application, though exploitation is difficult and requires interaction from a user other than the attacker. Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all data accessible to Oracle Agile Engineering Data Management.
Critical Impact
Successful exploitation permits unauthorized read and write access to all data accessible to Oracle Agile Engineering Data Management, impacting confidentiality and integrity of engineering data.
Affected Products
- Oracle Agile Engineering Data Management 6.2.1
- Component: Install
- Product family: Oracle Supply Chain
Discovery Timeline
- 2026-07-21 - CVE-2026-61190 published to NVD
- 2026-07-21 - Last updated in NVD database
- July 2026 - Addressed in the Oracle Critical Patch Update
Technical Details for CVE-2026-61190
Vulnerability Analysis
The vulnerability resides in the Install component of Oracle Agile Engineering Data Management 6.2.1. An authenticated attacker holding low-level privileges can reach the vulnerable functionality over HTTP. Exploitation is not straightforward and depends on convincing a separate user to perform an action, placing this issue in the user-assisted attack category.
When the exploitation chain succeeds, the attacker gains full read access to all data the application can reach. The attacker also gains the ability to create, delete, or modify records across the Agile Engineering Data Management dataset. Availability of the service is not affected according to the published CVSS vector.
Engineering data managed by this product typically includes product designs, bill-of-materials information, change orders, and supplier data. Loss of integrity in this dataset can cascade into manufacturing errors and supply chain disruption.
Root Cause
Oracle has not published the specific root cause in public advisories. The Install component handling network-reachable HTTP requests appears to accept input that leads to broad data access when combined with user interaction from another authenticated user. Refer to the Oracle Critical Patch Update - July 2026 for vendor-authoritative details.
Attack Vector
The attack vector is Network via HTTP. The attacker must already possess low-level credentials on the target application. The attacker then triggers a workflow that requires a second user, likely with different privileges, to interact with attacker-controlled content or requests. That interaction completes the exploitation chain, granting the attacker unauthorized read and write access to Agile Engineering Data Management data.
No public proof-of-concept exploit exists for CVE-2026-61190. The EPSS score is 0.258% at the 17.4 percentile, indicating a low probability of exploitation observed in the near term.
Detection Methods for CVE-2026-61190
Indicators of Compromise
- Unexpected HTTP requests to the Oracle Agile Engineering Data Management Install component originating from low-privileged user sessions.
- Anomalous create, update, or delete operations against engineering records, change orders, or bill-of-materials entries.
- Authentication sessions performing bulk read operations that exceed the user's typical role scope.
Detection Strategies
- Enable and review Oracle Agile EDM application audit logs for actions performed under low-privilege accounts that touch high-value records.
- Correlate web server access logs with application-level authorization decisions to identify privilege mismatches.
- Baseline normal user activity on the Install component and alert on deviations involving cross-user request sequences.
Monitoring Recommendations
- Forward Oracle Agile EDM and fronting web server logs into a centralized SIEM for retention and correlation.
- Monitor for repeated failed or unusual HTTP requests to Install component endpoints prior to successful sensitive operations.
- Alert when a single account performs both a request-preparation action and a downstream action normally requiring separate user interaction within a short window.
How to Mitigate CVE-2026-61190
Immediate Actions Required
- Apply the fixes provided in the Oracle Critical Patch Update - July 2026 to Oracle Agile Engineering Data Management 6.2.1.
- Inventory all Oracle Agile EDM 6.2.1 deployments, including test and staging environments, and prioritize patching internet-adjacent instances.
- Review and tighten role assignments so that low-privilege accounts cannot reach the Install component over HTTP.
Patch Information
Oracle addressed CVE-2026-61190 as part of the July 2026 Critical Patch Update. Administrators should download and apply the patch bundle for Oracle Agile Engineering Data Management 6.2.1 as documented in the Oracle Critical Patch Update advisory. Validate the patch in a non-production environment before deploying to production, and confirm that dependent Oracle Supply Chain components remain functional post-patch.
Workarounds
- Restrict network access to Oracle Agile EDM HTTP endpoints to trusted internal networks and VPN segments.
- Enforce multi-factor authentication for all Oracle Agile EDM users to raise the cost of low-privileged credential abuse.
- Educate users with elevated privileges about the risk of interacting with links or content sent by low-privileged colleagues, since exploitation requires their participation.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

