Description
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: RTP Proxy). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Converged Application Server executes to compromise Oracle Communications Converged Application Server. While the vulnerability is in Oracle Communications Converged Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the RTP Proxy component of Oracle Communications Converged Application Server 8.3 allows an attacker with high‑privileged local access to the host infrastructure to take full control of the application server. The flaw is a permission‑management weakness that permits escalation of privileges within the server process, leading to complete compromise of confidentiality, integrity, and availability. Successful exploitation results in a server takeover and can potentially affect other products shared by the same infrastructure because the vulnerability’s impact scope can change.

Affected Systems

Oracle Communications Converged Application Server 8.3, specifically the RTP Proxy component. The vulnerability may also impact additional components of the application server or other applications running on the same host if the scope changes during exploitation.

Risk and Exploitability

The CVSS v3.1 base score of 7.5 signals a high severity for confidentiality, integrity, and availability. The EPSS score is below 1 %, and the vulnerability is not listed in CISA’s KEV catalog, indicating that widespread exploitation has not been observed. The attack vector is inferred to be local, requiring an attacker who already has high‑privileged credentials on the host. Even though the opportunity for exploitation is limited, the resulting full control of the server makes this a high‑risk vulnerability if the conditions are met.

Generated by OpenCVE AI on August 5, 2026 at 01:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch for Oracle Communications Converged Application Server 8.3 that addresses the RTP Proxy flaw
  • Ensure that only trusted administrators have privileged access to the host infrastructure and enforce strict role‑based access controls
  • Segment the network to isolate the application server from other critical assets and limit lateral movement
  • Configure monitoring and logging to detect unauthorized activity related to the application server

Generated by OpenCVE AI on August 5, 2026 at 01:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Communications Converged Application Server 8.3 RTP Proxy
Weaknesses CWE-284
CWE-285

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title High Privilege Local Exploit in Oracle Communications Converged Application Server RTP Proxy
Weaknesses CWE-284

Thu, 30 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title High Privilege Local Exploit in Oracle Communications Converged Application Server RTP Proxy
Weaknesses CWE-284

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title High Privilege Remote Exploitation in Oracle Communications Converged Application Server RTP Proxy
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title High Privilege Remote Exploitation in Oracle Communications Converged Application Server RTP Proxy
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: RTP Proxy). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Converged Application Server executes to compromise Oracle Communications Converged Application Server. While the vulnerability is in Oracle Communications Converged Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle communications Converged Application Server
CPEs cpe:2.3:a:oracle:communications_converged_application_server:8.3:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle communications Converged Application Server
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Communications Converged Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T19:22:36.260Z

Reserved: 2026-07-08T15:52:20.741Z

Link: CVE-2026-61226

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:45:04Z

Weaknesses