Description
Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mobile). Supported versions that are affected are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8 and 25.12.0.0.0-25.12.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System. While the vulnerability is in Oracle Utilities Network Management System, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Utilities Network Management System accessible data as well as unauthorized read access to a subset of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the mobile component of Oracle Utilities Network Management System. It allows an unauthenticated attacker with network access via HTTP to perform unauthorized update, insert, delete operations and read access to a subset of data. The flaw is easily exploitable and its CVSS 3.1 base score of 7.2 reflects confidentiality and integrity impact with scope change, meaning additional products may also be affected.

Affected Systems

The affected product is Oracle Utilities Network Management System under Oracle Utilities Applications, specifically its Mobile component. Versions 2.5.0.1.0 through 2.5.0.1.17, 2.5.0.2.0 through 2.5.0.2.11, 2.6.0.1.0 through 2.6.0.1.12, 2.6.0.2.0 through 2.6.0.2.8, and 25.12.0.0.0 through 25.12.0.0.2 are impacted.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.2, indicating moderate to high severity. EPSS is < 1 %, showing a low probability of exploitation currently, and it is not listed in CISA's KEV catalog. The likely attack vector is unauthenticated access over HTTP, meaning it can be triggered by anyone on the network path. Successful exploitation enables attackers to modify or delete critical configuration data and read sensitive information, potentially cascading to other products due to the scope change. Because no workaround is provided, immediate remediation is recommended.

Generated by OpenCVE AI on August 4, 2026 at 17:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch released by Oracle to the affected versions
  • Restrict trusted IPs or secure via VPN and enforce TLS encryption
  • Enable or review application‑level access controls and detailed auditing to detect unauthorized data changes

Generated by OpenCVE AI on August 4, 2026 at 17:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Exposure via Unauthenticated HTTP Access in Oracle Utilities Network Management System

Sat, 01 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Exposure via Unauthenticated HTTP Access in Oracle Utilities Network Management System

Wed, 29 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification in Oracle Utilities Network Management System Mobile Component
Weaknesses CWE-863

Fri, 24 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification in Oracle Utilities Network Management System Mobile Component
Weaknesses CWE-863

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mobile). Supported versions that are affected are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8 and 25.12.0.0.0-25.12.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System. While the vulnerability is in Oracle Utilities Network Management System, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Utilities Network Management System accessible data as well as unauthorized read access to a subset of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle utilities Network Management System
CPEs cpe:2.3:a:oracle:utilities_network_management_system:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle utilities Network Management System
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Utilities Network Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:17:16.766Z

Reserved: 2026-05-18T15:55:10.315Z

Link: CVE-2026-46981

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:43.146Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:03.123

Modified: 2026-08-06T15:07:32.040

Link: CVE-2026-46981

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T18:00:14Z

Weaknesses