Description
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with network access via TLS to compromise Oracle Communications Converged Application Server. While the vulnerability is in Oracle Communications Converged Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Communications Converged Application Server 8.3 contains a flaw in its Security component that permits a highly privileged attacker with network access over TLS to gain full control of the server. The weakness allows the attacker to compromise confidentiality, integrity, and availability, effectively resulting in a complete takeover. This access control failure is identified as CWE‑284.

Affected Systems

The affected product is Oracle Communications Converged Application Server version 8.3. No other Oracle product versions are listed as affected, but the CVE notes that the vulnerability may impact additional products due to a scope change.

Risk and Exploitability

The CVSS base score of 8.0 indicates high severity, while the EPSS score of less than 1 % suggests a low but nonzero likelihood of exploitation in the field. The vulnerability is not present in the CISA KEV catalog. The exploit is performed over a network connection using TLS, requiring a remote attacker to send crafted TLS traffic; no local compromise is necessary.

Generated by OpenCVE AI on August 4, 2026 at 16:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in the CPU July 2026 update for Oracle Communications Converged Application Server 8.3
  • Restrict TLS traffic to the server to trusted internal IP ranges or enable mutual TLS authentication to reduce the attack surface
  • Enable comprehensive monitoring and logging for privileged actions on the server to detect and respond to potential takeover incidents

Generated by OpenCVE AI on August 4, 2026 at 16:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Server Takeover of Oracle Communications Converged Application Server 8.3 via TLS

Sun, 02 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Server Takeover of Oracle Communications Converged Application Server 8.3 via TLS

Mon, 27 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title High‑Privilege Remote Takeover via TLS in Oracle Communications Converged Application Server 8.3

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title High‑Privilege Remote Takeover via TLS in Oracle Communications Converged Application Server 8.3

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with network access via TLS to compromise Oracle Communications Converged Application Server. While the vulnerability is in Oracle Communications Converged Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle communications Converged Application Server
CPEs cpe:2.3:a:oracle:communications_converged_application_server:8.3:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle communications Converged Application Server
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Communications Converged Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T19:22:02.543Z

Reserved: 2026-07-08T15:52:20.741Z

Link: CVE-2026-61224

cve-icon Vulnrichment

Updated: 2026-07-22T19:21:57.850Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:15:03Z

Weaknesses