Description
Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as unauthorized read access to a subset of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-09-15
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized read and write of proxy configuration data via HTTP by low‑privileged users
Action: Patch ASAP
AI Analysis

Impact

A flaw in Oracle Communications Cloud Native Core Security Edge Protection Proxy allows an attacker who can reach the proxy through ordinary HTTP traffic to perform unauthorized update, insert or delete operations on the proxy’s data and to read protected data. The vulnerability is easy to exploit once network access is obtained and does not require elevated privileges. It results in loss of integrity and confidentiality for the affected data. The weakness is rooted in improper access control.

Affected Systems

The vulnerability affects Oracle Communications Cloud Native Core Security Edge Protection Proxy versions 26.1.200 and 25.2.201. Users running these builds should consider them vulnerable until a fix is applied.

Risk and Exploitability

The CVSS v3.1 base score of 5.4 indicates a moderate risk, with only confidentiality and integrity impacted. The EPSS reflects a very low probability of exploitation (<1%). The vulnerability is not yet listed in CISA’s KEV catalog. An attacker can exploit it by sending crafted HTTP requests to the exposed interface; no additional co‑existing vulnerabilities are required, and the attack is feasible for a low‑privileged network user.

Generated by OpenCVE AI on September 22, 2026 at 18:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade to a non‑affected version as soon as it is available
  • Restrict HTTP access to the SEPP installation by firewalls or network segmentation, allowing only trusted IP ranges
  • Configure robust authentication and authorization controls so that only privileged accounts can modify or read sensitive data
  • Regularly audit SEPP logs for unauthorized read or write attempts and respond to any anomalies

Generated by OpenCVE AI on September 22, 2026 at 18:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Low‑privileged HTTP Attack Enables Unauthorized Access to Oracle SEPP Data

Tue, 22 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unauthorized data modification via HTTP in Oracle SEPP
Weaknesses CWE-285

Tue, 22 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Sun, 20 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title Unauthorized data modification via HTTP in Oracle SEPP
Weaknesses CWE-285

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Modification in Oracle SEPP
Weaknesses CWE-200
CWE-284

Wed, 16 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Modification in Oracle SEPP
Weaknesses CWE-200
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as unauthorized read access to a subset of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle communications Cloud Native Core Security Edge Protection Proxy
CPEs cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:25.2.201:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:26.1.200:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle communications Cloud Native Core Security Edge Protection Proxy
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Communications Cloud Native Core Security Edge Protection Proxy
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-22T14:46:04.106Z

Reserved: 2026-08-31T15:40:57.358Z

Link: CVE-2026-83419

cve-icon Vulnrichment

Updated: 2026-09-22T14:45:48.153Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:50.343

Modified: 2026-09-22T15:17:18.187

Link: CVE-2026-83419

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:00:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor