Description
Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Security). Supported versions that are affected are 2.4.0.1.0-2.4.0.1.32, 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.2.0-2.6.0.2.7 and 25.12.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Network Management System. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Utilities Network Management System accessible data as well as unauthorized read access to a subset of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the security component of Oracle Utilities Network Management System enables an attacker with only low privilege and direct HTTP access to perform unauthorized update, insert, delete or read operations on data stored by the system. The vulnerability is exploitable without privileged credentials, but it requires manual interaction by a separate, non‑attacker user to trigger the action. Successful exploitation can result in altered or removed data and the disclosure of a subset of system data, impacting both data integrity and confidentiality.

Affected Systems

The vulnerability affects Oracle Utilities Network Management System versions 2.4.0.1.0 through 2.4.0.1.32, 2.5.0.1.0 through 2.5.0.1.17, 2.5.0.2.0 through 2.5.0.2.11, 2.6.0.2.0 through 2.6.0.2.7, and the 25.12.0.0.0 release. These versions are part of the Oracle Utilities Applications stack.

Risk and Exploitability

The CVSS base score of 4.6 indicates moderate risk; the EPSS score of less than 1% shows a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires network reachability via HTTP and a separate user action, so the attack surface is limited. Nonetheless, because the outcome includes unauthorized data modification and partial data disclosure, organizations should consider the exposed data as potentially sensitive.

Generated by OpenCVE AI on August 4, 2026 at 05:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Utilities Network Management System security patch as released by Oracle.
  • Restrict HTTP access to the Management System to trusted internal networks or a secure VPN, blocking unauthenticated external connections.
  • Enforce strict least‑privilege access controls for all accounts interacting with the system and disable or monitor any unused administrative privileges.
  • Implement firewall or access‑control rules to block inbound HTTP traffic to the system from untrusted sources.
  • Monitor logs for anomalous update, insert, delete, or read operations, and investigate any suspicious activity.

Generated by OpenCVE AI on August 4, 2026 at 05:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Allows Unauthorized Data Modification and Partial Disclosure in Oracle Utilities Network Management System

Wed, 29 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle Utilities Network Management System

Fri, 24 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle Utilities Network Management System

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Security). Supported versions that are affected are 2.4.0.1.0-2.4.0.1.32, 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.2.0-2.6.0.2.7 and 25.12.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Network Management System. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Utilities Network Management System accessible data as well as unauthorized read access to a subset of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle utilities Network Management System
CPEs cpe:2.3:a:oracle:utilities_network_management_system:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:utilities_network_management_system:25.12.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle utilities Network Management System
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Utilities Network Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:18:09.593Z

Reserved: 2026-05-18T15:55:10.313Z

Link: CVE-2026-46948

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:47.061Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:02.513

Modified: 2026-08-06T14:59:52.977

Link: CVE-2026-46948

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:30:04Z

Weaknesses