Description
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that are affected are 8.2 and 8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications Converged Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Oracle Communications Converged Application Server, located in the Core component, can be exploited by an unauthenticated attacker with network access over TCP/IP. If successfully exploited, the attacker is likely to gain full control of the server, potentially exposing all sensitive data stored or processed by the application. This weakness is due to improper authorization handling and is classified under CWE‑269, CWE‑287, and CWE‑306.

Affected Systems

The affected products are Oracle Communications Converged Application Server versions 8.2 and 8.3. No other versions or product lines are listed as affected. Oracle Communications, as the vendor, has identified the issue in the 8.2 and 8.3 releases.

Risk and Exploitability

The CVSS 8.1 score reflects high severity, with impacts on confidentiality, integrity, and availability. Based on the description, the attack vector is inferred to be remote over TCP/IP, with no authentication required and no user interaction needed. The EPSS score of less than 1% indicates that exploitation attempts are expected to be rare, but the potential impact remains significant. The vulnerability is not listed in CISA's KEV catalog; however, due to its high impact and the ability for an unauthenticated attacker to reach the vulnerable component from the network, system owners should treat it as a notable risk.

Generated by OpenCVE AI on August 4, 2026 at 16:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Communications Converged Application Server 8.2 and 8.3 as published in the security alert
  • Restrict network access to the server to trusted IP addresses or internal networks to prevent unauthenticated TCP/IP connections
  • Enable and review detailed logging on the server for authentication attempts, anomalies, and unauthorized activity

Generated by OpenCVE AI on August 4, 2026 at 16:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unrestricted TCP/IP Access Enables Server Compromise in Oracle Communications Converged Application Server

Thu, 30 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unrestricted TCP/IP Access Enables Server Compromise in Oracle Communications Converged Application Server

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that are affected are 8.2 and 8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications Converged Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle communications Converged Application Server
CPEs cpe:2.3:a:oracle:communications_converged_application_server:8.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_converged_application_server:8.3:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle communications Converged Application Server
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Communications Converged Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T19:23:21.875Z

Reserved: 2026-07-08T15:52:20.741Z

Link: CVE-2026-61225

cve-icon Vulnrichment

Updated: 2026-07-22T19:23:17.230Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:15:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function