Description
Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Diameter Gateway and SDK). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications BRM - Elastic Charging Engine executes to compromise Oracle Communications BRM - Elastic Charging Engine. Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker with low privileges who has logged on to the infrastructure where Oracle Communications BRM – Elastic Charging Engine runs to compromise the application. A successful exploit can lead to a full takeover, resulting in confidentiality, integrity, and availability losses for the entire system. This weakness corresponds to CWE-269: Least Privilege Violation.

Affected Systems

Oracle Communications BRM – Elastic Charging Engine versions 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, and 15.2.0.0.0 are affected.

Risk and Exploitability

With a CVSS score of high severity. The EPSS score of less than 1% indicates that the vulnerability is not listed in the CISA KEV catalog. The attack vector is local: an attacker who has logged onto the infrastructure without any user interaction. Once exploited, the attacker can take over the application and potentially elevate privileges within the system.

Generated by OpenCVE AI on August 4, 2026 at 02:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or upgrade to a non‑affected version of Oracle Communications BRM – Elastic Charging Engine.
  • Restrict local system access by enforcing least‑privilege policies and ensuring that only trusted users can log onto the infrastructure hosting the application.
  • Monitor authentication logs and application activity for signs of unauthorized use and alert security teams if anomalous behavior is detected.

Generated by OpenCVE AI on August 4, 2026 at 02:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Local Exploit Enables Full Application Takeover in Oracle Communications BRM – Elastic Charging Engine

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Elastic Charging Engine Local Privilege Escalation Leading to Full System Takeover
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Elastic Charging Engine Local Privilege Escalation Leading to Full System Takeover
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Diameter Gateway and SDK). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications BRM - Elastic Charging Engine executes to compromise Oracle Communications BRM - Elastic Charging Engine. Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle communications Brm - Elastic Charging Engine
CPEs cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:15.0.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:15.0.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:15.1.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:15.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle communications Brm - Elastic Charging Engine
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Communications Brm - Elastic Charging Engine
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:24:56.679Z

Reserved: 2026-07-08T15:51:55.610Z

Link: CVE-2026-61053

cve-icon Vulnrichment

Updated: 2026-07-24T14:24:51.175Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management