Description
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: BRM Server). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Billing and Revenue Management executes to compromise Oracle Communications Billing and Revenue Management. Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows a low‑privileged user who has logged on to the underlying infrastructure to gain complete control over the Oracle Communications Billing and Revenue Management (BRM) Server. A successful exploitation results in the attacker taking over the BRM service, compromising confidentiality, integrity and availability of the charging and billing functions. The weakness resides in a local privilege escalation flaw that enables the attacker to bypass normal security controls and perform unauthorized operations.

Affected Systems

Oracle Communications Billing and Revenue Management servers running versions 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0 are vulnerable. These versions are deployed by organizations using Oracle’s communications billing solution but the information does not specify if any later releases contain a fix.

Risk and Exploitability

The CVSS 3.1 Base Score of 7.8 reflects significant impact to all three core security properties. With an AV:L vector the exploit requires local login but low effort and no user interaction, making it relatively easy to execute. The EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation today, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, because the flaw permits full takeover of a critical billing system, it represents a high operational risk for any organization that can be compromised by a local attacker.

Generated by OpenCVE AI on August 4, 2026 at 01:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Communications Billing and Revenue Management patch or upgrade to a version that contains the fix for CVE-2026-61091
  • Restrict local access to the BRM Server by enforcing least‑privilege policies and block unused administrative accounts
  • Review and enforce separation of duties for users with local infrastructure access to mitigate potential exploitation

Generated by OpenCVE AI on August 4, 2026 at 01:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Communications Billing and Revenue Management Server

Thu, 30 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Communications Billing and Revenue Management Server

Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Communications Billing and Revenue Management Server
Weaknesses CWE-798

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Communications Billing and Revenue Management Server
Weaknesses CWE-269
CWE-798

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: BRM Server). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Billing and Revenue Management executes to compromise Oracle Communications Billing and Revenue Management. Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle communications Billing And Revenue Management
CPEs cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.0.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.0.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.1.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle communications Billing And Revenue Management
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Communications Billing And Revenue Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T13:59:28.536Z

Reserved: 2026-07-08T15:51:55.612Z

Link: CVE-2026-61091

cve-icon Vulnrichment

Updated: 2026-07-24T13:58:28.686Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-07-21T22:18:40.110

Modified: 2026-07-24T15:19:03.037

Link: CVE-2026-61091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:00:12Z

Weaknesses
  • CWE-269

    Improper Privilege Management