Executive brief
Oracle Utilities Network Management System is a platform used by utility companies to manage power grids and respond to outages. A vulnerability in its mobile component could allow an authorized user with low-level permissions to view sensitive data they are not supposed to see. This could lead to the exposure of internal operational information or customer data.
Technical details
An information disclosure vulnerability exists in the Mobile component of Oracle Utilities Network Management System. The flaw is easily exploitable by an attacker with low-level privileges and network access via HTTP. Successful exploitation allows the attacker to bypass intended access controls to perform unauthorized read operations on a subset of the system's data. Affected versions include various releases across the 2.5.x, 2.6.x, and 25.12.x branches. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Utilities Network Management System 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, 25.12.0.0.0-25.12.0.0.2
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory