CVE-2026-61187: Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile Engineering Data Management. in Oracle Corporat
CVE-2026-61187 is a vulnerability in Oracle Agile Engineering Data Management version 6.2.1 that allows a low privileged attacker with logon access to the infrastructure to cause a partial denial of service. Exploitation requires human interaction from a user other than the attacker. The vulnerability impacts availability but does not affect confidentiality or integrity. The CVSS 3.1 base score is 2.8, indicating a low severity issue.
AI Analysis
Technical Summary
This vulnerability affects Oracle Agile Engineering Data Management version 6.2.1. It allows a low privileged attacker who has logon access to the infrastructure where the product runs to compromise the system, resulting in a partial denial of service. Successful exploitation requires user interaction from a person other than the attacker. The CVSS vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L) reflects that the attack vector is local, with low complexity, requiring low privileges and user interaction, impacting only availability. No confidentiality or integrity impacts are reported. The vendor advisory does not explicitly confirm patch availability or remediation status for this specific vulnerability in the provided content.
Potential Impact
The vulnerability can lead to unauthorized partial denial of service of Oracle Agile Engineering Data Management, potentially disrupting availability of the service. There is no impact on confidentiality or integrity. Exploitation requires local access with low privileges and user interaction, limiting the scope and ease of exploitation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory at https://www.oracle.com/security-alerts/cpujul2026.html for current remediation guidance. Oracle strongly recommends applying Critical Patch Updates promptly. Until a patch is applied, limit logon access to trusted users and educate users to avoid interaction with suspicious prompts or content that could trigger the vulnerability.
CVE-2026-61187: Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile Engineering Data Management. in Oracle Corporat
Description
CVE-2026-61187 is a vulnerability in Oracle Agile Engineering Data Management version 6.2.1 that allows a low privileged attacker with logon access to the infrastructure to cause a partial denial of service. Exploitation requires human interaction from a user other than the attacker. The vulnerability impacts availability but does not affect confidentiality or integrity. The CVSS 3.1 base score is 2.8, indicating a low severity issue.
CVSS v3.1
Score 2.8low
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability affects Oracle Agile Engineering Data Management version 6.2.1. It allows a low privileged attacker who has logon access to the infrastructure where the product runs to compromise the system, resulting in a partial denial of service. Successful exploitation requires user interaction from a person other than the attacker. The CVSS vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L) reflects that the attack vector is local, with low complexity, requiring low privileges and user interaction, impacting only availability. No confidentiality or integrity impacts are reported. The vendor advisory does not explicitly confirm patch availability or remediation status for this specific vulnerability in the provided content.
Potential Impact
The vulnerability can lead to unauthorized partial denial of service of Oracle Agile Engineering Data Management, potentially disrupting availability of the service. There is no impact on confidentiality or integrity. Exploitation requires local access with low privileges and user interaction, limiting the scope and ease of exploitation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory at https://www.oracle.com/security-alerts/cpujul2026.html for current remediation guidance. Oracle strongly recommends applying Critical Patch Updates promptly. Until a patch is applied, limit logon access to trusted users and educate users to avoid interaction with suspicious prompts or content that could trigger the vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- oracle
- Date Reserved
- 2026-07-08T15:52:20.739Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","vendor":"Oracle"}]
Threat ID: 6a5fee379c2644c7f8d5d5d6
Added to database: 07/21/2026, 22:09:59 UTC
Last enriched: 07/30/2026, 05:07:38 UTC
Last updated: 09/01/2026, 22:52:13 UTC
Views: 66
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.