Executive brief
Oracle Utilities Network Management System, a platform used by utility companies to manage power grids and outages, contains a security vulnerability in its security component. An attacker with low-level access could trick a legitimate user into performing actions that allow the attacker to view, modify, or delete sensitive utility data. While this requires interaction from a victim, it could lead to unauthorized changes to operational information or data exposure.
Technical details
This vulnerability exists in the Security component of Oracle Utilities Network Management System. It is classified as easily exploitable via the network using HTTP, though it requires a low-privileged account and human interaction (UI:R) from a victim other than the attacker. The CVSS vector (AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N) suggests a flaw such as Cross-Site Request Forgery (CSRF) or a similar client-side injection that allows an attacker to perform unauthorized data manipulation (Create, Update, Delete) and limited data retrieval. Affected versions include 2.4.x, 2.5.x, 2.6.x, and 25.12.x. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation.
Affected products
- Oracle Utilities Network Management System 2.4.0.1.0-2.4.0.1.32, 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.2.0-2.6.0.2.7, 25.12.0.0.0
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this CVE.
- 2026-07-21: disclosed