Vulnerability in Oracle Agile Engineering Data Management by Oracle
CVE-2026-70709

4.8MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70709?

A vulnerability exists in Oracle Agile Engineering Data Management, specifically within the Engineering Communication Interface component. This issue enables unauthenticated attackers with network access via HTTP to potentially compromise the system. Successful exploitation may lead to unauthorized update, insert, or delete operations on accessible data, as well as unwarranted read access to a subset of data. Organizations using version 6.2.1 are encouraged to review the advisory for potential impacts and mitigation strategies.

Affected Version(s)

Oracle Agile Engineering Data Management 6.2.1

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.