Description
Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mobile). Supported versions that are affected are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8 and 25.12.0.0.0-25.12.0.0.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Network Management System. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Mobile component of Oracle Utilities Network Management System that permits a low‑privileged attacker who can reach the component over HTTP to read a subset of data that should be restricted. The flaw does not enable code execution or privilege escalation; it simply allows the attacker to view confidential information through an unauthorized read path. The weakness is a classic example of improper authorization, as indicated by the CWE-284 identifier.

Affected Systems

Oracle Utilities Network Management System is impacted. The affected release range includes 2.5.0.1.0 through 2.5.0.1.17, 2.5.0.2.0 through 2.5.0.2.11, 2.6.0.1.0 through 2.6.0.1.12, 2.6.0.2.0 through 2.6.0.2.8, and 25.12.0.0.0 through 25.12.0.0.2.

Risk and Exploitability

The CVSS 3.1 base score of 4.3 marks the vulnerability as moderate, driven primarily by a confidentiality impact. The EPSS score of < 1% indicates that attacks are expected to be rare, and the vulnerability is not listed in the CISA KEV catalog. Attackers need only network connectivity to the HTTP port exposed by the Mobile component and low privileges on the target system. No additional access or user interaction is required beyond the initial HTTP request, making the exploit path straightforward once network access is established.

Generated by OpenCVE AI on August 4, 2026 at 05:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch for Oracle Utilities Network Management System that is distributed in the July 2026 Oracle CPU alert at https://www.oracle.com/security-alerts/cpujul2026.html
  • Constrain HTTP access to the Mobile component by applying firewall rules or network segmentation so that only trusted hosts can reach it
  • If the Mobile functionality is not required for business operations, disable or uninstall the component

Generated by OpenCVE AI on August 4, 2026 at 05:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Network Read Access Vulnerability in Oracle Utilities Network Management System Mobile Component

Sun, 26 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Network Read Access Vulnerability in Oracle Utilities Network Management System Mobile Component

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mobile). Supported versions that are affected are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8 and 25.12.0.0.0-25.12.0.0.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Network Management System. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle utilities Network Management System
CPEs cpe:2.3:a:oracle:utilities_network_management_system:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle utilities Network Management System
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Utilities Network Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:17:26.188Z

Reserved: 2026-05-18T15:55:10.315Z

Link: CVE-2026-46980

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:43.858Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:03.007

Modified: 2026-08-06T15:00:06.320

Link: CVE-2026-46980

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:30:04Z

Weaknesses