Description
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). Supported versions that are affected are 8.2 and 8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications Converged Application Server. While the vulnerability is in Oracle Communications Converged Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The anomaly originates in the Security component of Oracle Communications Converged Application Server versions 8.2 and 8.3. An unauthenticated attacker who can reach the server over the network can compromise the server. The vulnerability allows full takeover, compromising confidentiality, integrity and availability for the application and potentially for other products if the scope changes.

Affected Systems

Oracle Communications Converged Application Server 8.2 and 8.3 are affected. The advisory notes that if the vulnerability's scope changes, it may also impact other products in the environment.

Risk and Exploitability

The CVSS 3.1 base score of 9.0 (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H) classifies this as a critical issue. Exploitation requires only network access and is difficult, and the EPSS score of less than 1% indicates a low probability that the vulnerability is currently being targeted. Although it is not included in the CISA KEV catalog, the potential for total server takeover makes it a high‑risk concern.

Generated by OpenCVE AI on August 5, 2026 at 01:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied security patch for Oracle Communications Converged Application Server 8.2 or 8.3.
  • Restrict inbound TCP/IP traffic to the server, using firewalls or VPNs to limit connections to trusted hosts.
  • Enforce strict authentication and role‑based access controls on the application server, ensuring all privileged operations require verified credentials.
  • Monitor system and application logs for anomalous activity and enable intrusion detection if available.

Generated by OpenCVE AI on August 5, 2026 at 01:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network‑Driven Server Takeover in Oracle Communications Converged Application Server
Weaknesses CWE-269
CWE-287

Tue, 04 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Vulnerability Enabling Full Server Takeover in Oracle Communications Converged Application Server
Weaknesses CWE-284
CWE-306

Thu, 30 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Vulnerability Enabling Full Server Takeover in Oracle Communications Converged Application Server
Weaknesses CWE-284
CWE-306

Mon, 27 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Access Compromise in Oracle Communications Converged Application Server 8.x
Weaknesses CWE-284
CWE-287

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Access Compromise in Oracle Communications Converged Application Server 8.x
Weaknesses CWE-284
CWE-287

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). Supported versions that are affected are 8.2 and 8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications Converged Application Server. While the vulnerability is in Oracle Communications Converged Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle communications Converged Application Server
CPEs cpe:2.3:a:oracle:communications_converged_application_server:8.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_converged_application_server:8.3:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle communications Converged Application Server
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Communications Converged Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T19:19:57.655Z

Reserved: 2026-07-08T15:52:20.741Z

Link: CVE-2026-61223

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:15:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-287

    Improper Authentication