Description
Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Solution Designer). Supported versions that are affected are 8.0.0.7.0-8.3.0.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design. Successful attacks of this vulnerability can result in takeover of Oracle Communications Service Catalog and Design. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Solution Designer component of Oracle Communications Service Catalog and Design allows a low‑privileged attacker with network access via HTTP to compromise the application. The vulnerability permits the attacker to take over the system, potentially impacting confidentiality, integrity, and availability. The weakness arises from insufficient permission checks, broken authorization, incorrect authentication handling, and missing access control.

Affected Systems

Oracle Communications Service Catalog and Design from Oracle Corporation; versions from 8.0.0.7.0 through 8.3.0.2.0 are vulnerable and may let this exploit succeed.

Risk and Exploitability

The CVSS base score of 8.8 indicates a high‑severity risk. The EPSS score is below 1 % and the vulnerability is not listed in CISA KEV, which may lower the immediate public exploitation likelihood. Nonetheless, the ability to compromise the system with low privilege over a network‑exposed HTTP endpoint and the potential for complete takeover suggests that a determined adversary could leverage this flaw if access is attainable.

Generated by OpenCVE AI on August 4, 2026 at 01:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch or update released by Oracle in the July 2026 security update for the affected versions.
  • Disable or restrict use of the Solution Designer feature, or enforce mandatory authentication before allowing its use if the feature is required.
  • Restrict inbound HTTP traffic to trusted networks only, applying firewall or IP‑whitelisting rules to block unintended access.

Generated by OpenCVE AI on August 4, 2026 at 01:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Allows Full Compromise of Oracle Communications Service Catalog and Design

Sun, 02 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Remote Code Execution in Oracle Communications Service Catalog and Design

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Remote Code Execution in Oracle Communications Service Catalog and Design

Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Enables Full Control of Oracle Communications Service Catalog

Sun, 26 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Enables Full Control of Oracle Communications Service Catalog

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Solution Designer). Supported versions that are affected are 8.0.0.7.0-8.3.0.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design. Successful attacks of this vulnerability can result in takeover of Oracle Communications Service Catalog and Design. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle communications Service Catalog And Design
CPEs cpe:2.3:a:oracle:communications_service_catalog_and_design:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle communications Service Catalog And Design
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Communications Service Catalog And Design
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:11:33.081Z

Reserved: 2026-07-08T15:51:55.615Z

Link: CVE-2026-61127

cve-icon Vulnrichment

Updated: 2026-07-23T19:11:21.600Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function