ZeroHour

CVE-2026-87259

niche

Local Privilege Escalation in Oracle Agile Engineering Data Management 6.2.1

CVSS 3.1
8.4 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87259 is a high-severity (CVSS 8.4) flaw in the Engineering Communication Interface component of Oracle Agile Engineering Data Management, part of Oracle Supply Chain, affecting version 6.2.1. It is exploited by a low-privileged attacker who already has a logon on the host or infrastructure where the product executes, making it a local privilege-escalation-style weakness rather than a remotely reachable flaw. Because of a scope change, a successful attack can compromise not only Agile EDM but also significantly impact additional products on the same infrastructure. The attacker gains unauthorized ability to create, delete, or modify critical data, as well as full read access to all data accessible through the product; availability is not affected. The vulnerability is not in the CISA KEV catalog, no public proof of concept is known, and there is no evidence of in-the-wild exploitation.

What to do: Apply the Oracle Critical Patch Update that remediates this issue as soon as Oracle releases it, and check the Oracle advisory for the fixed build of Agile EDM 6.2.1. In the meantime, restrict and audit local OS accounts with logon access to servers hosting Agile EDM, enforce least privilege on those hosts, and monitor for unauthorized creation, deletion, or modification of engineering data via the Engineering Communication Interface.

Affected
Oracle Agile Engineering Data Management (Oracle Supply Chain, Engineering Communication Interface component)
Estimated exposure
nichelikely hundreds to low thousands of enterprise installations worldwide (no public deployment counts) — Oracle Agile EDM is a specialized on-premise engineering/PLM product typically deployed only at large manufacturing enterprises, and the local attack vector further limits the practically exposed set, so the reachable population is small…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. While the vulnerability is in Oracle Agile Engineering Data Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.