Description
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform). Supported versions that are affected are 15.0.0.0.0-15.0.1.0.0 and 15.1.0.0.0-15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Billing and Revenue Management executes to compromise Oracle Communications Billing and Revenue Management. Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Platform component of Oracle Communications Billing and Revenue Management. It allows a low‑privileged user who can log into the infrastructure that hosts the product to gain full control over the application. Successful exploitation leads to a complete takeover, compromising confidentiality, integrity, and availability for the entire instance. The CVSS vector indicates a local attack with low attack complexity, low privileges, and no user interaction, yet the impact is high in all three security dimensions.

Affected Systems

Oracle Communications Billing and Revenue Management version 15.0.0.0.0 through 15.0.1.0.0 and 15.1.0.0.0 through 15.2.0.0.0 are affected.

Risk and Exploitability

The CVSS score is 7.8, indicating a high severity. The EPSS score of less than 1% shows that the probability of exploitation at any given time is currently low, and the vulnerability is not yet listed in CISA’s KEV catalogue. Nevertheless, because the attack requires only local access and low privileges, the risk remains significant for systems that expose local logon capabilities to less trusted users. The analyzer infers that successful exploitation would allow a local attacker to bypass all controls and fully compromise the application.

Generated by OpenCVE AI on August 4, 2026 at 01:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Communications CPU July 2026 update for Oracle Communications Billing and Revenue Management to address this flaw.
  • Restrict local account logon to administrative users only, ensuring that only trusted administrative accounts have access to the product’s infrastructure.
  • Enforce least privilege on all local accounts that can log on to the infrastructure and audit permissions regularly.
  • Implement network segmentation or firewall rules to limit local access to the servers hosting the application, reducing the attack surface.

Generated by OpenCVE AI on August 4, 2026 at 01:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Allowing Full Takeover in Oracle Communications Billing and Revenue Management

Thu, 30 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Allowing Full Takeover in Oracle Communications Billing and Revenue Management

Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Local Privileged Attack Enables Full Takeover of Oracle Communications Billing and Revenue Management
Weaknesses CWE-284
CWE-732

Fri, 24 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Local Privileged Attack Enables Full Takeover of Oracle Communications Billing and Revenue Management
Weaknesses CWE-284
CWE-732

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform). Supported versions that are affected are 15.0.0.0.0-15.0.1.0.0 and 15.1.0.0.0-15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Billing and Revenue Management executes to compromise Oracle Communications Billing and Revenue Management. Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle communications Billing And Revenue Management
CPEs cpe:2.3:a:oracle:communications_billing_and_revenue_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle communications Billing And Revenue Management
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Communications Billing And Revenue Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:40:19.085Z

Reserved: 2026-07-08T15:51:55.615Z

Link: CVE-2026-61126

cve-icon Vulnrichment

Updated: 2026-07-23T19:40:15.432Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management