Description
Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security). Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0 and 8.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Communications Unified Inventory Management product contains a flaw in its security component that allows a low‑privileged attacker with network access via HTTP to gain unauthorized access to critical data. Successful exploitation can result in full data access and the ability to create, modify, or delete records, thereby compromising both confidentiality and integrity of the system's data set.

Affected Systems

Affected versions include Oracle Communications Unified Inventory Management 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0, and 8.0.1. The vulnerability is present in the Security component that processes HTTP requests from clients connected to the product's web interface.

Risk and Exploitability

The CVSS 3.1 base score of 7.1 indicates a high impact on confidentiality and a moderate impact on integrity. The EPSS score of less than 1% indicates that the likelihood of exploitation is low, and the vulnerability is not listed in CISA’s KEV catalog. However, because the attack can be performed over the network using HTTP and requires minimal privileges, an attacker could gain significant access to sensitive data or alter records if the patch is not applied.

Generated by OpenCVE AI on August 2, 2026 at 19:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or update released in the July 2026 Oracle Critical Patch Update that addresses CVE‑2026‑61095.
  • Restrict HTTP access to the Oracle Communications Unified Inventory Management server to trusted IP ranges or enable firewall rules that block unauthorized connections.
  • Implement strict authentication and authorization controls for all web endpoints, ensuring that only users with appropriate roles can view or modify sensitive data.
  • If a patch is not immediately available, temporarily disable the exposed vulnerability endpoint or services that process HTTP requests until the fix can be deployed.
  • Monitor log files and network traffic for signs of attempted exploitation, and use intrusion detection to alert on anomalous activity.

Generated by OpenCVE AI on August 2, 2026 at 19:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low-Privilege HTTP Exploit in Oracle Communications Unified Inventory Management
Weaknesses CWE-285

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low-Privilege HTTP Exploit in Oracle Communications Unified Inventory Management
Weaknesses CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security). Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0 and 8.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle communications Unified Inventory Management
CPEs cpe:2.3:a:oracle:communications_unified_inventory_management:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_unified_inventory_management:7.5.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_unified_inventory_management:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_unified_inventory_management:7.7.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_unified_inventory_management:7.8.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_unified_inventory_management:8.0.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle communications Unified Inventory Management
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Communications Unified Inventory Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:21:29.943Z

Reserved: 2026-07-08T15:51:55.613Z

Link: CVE-2026-61095

cve-icon Vulnrichment

Updated: 2026-07-23T19:21:25.732Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:00:12Z

Weaknesses