Executive brief
Oracle Utilities Network Management System, a platform used by utility companies to manage power grids and outages, contains a vulnerability in its mobile component. An unauthorized person could use this flaw over the internet to view, change, or delete sensitive utility data. This could lead to inaccurate operational information or unauthorized modifications to system records, potentially impacting related business systems.
Technical details
A vulnerability exists in the Mobile component of Oracle Utilities Network Management System. The flaw is categorized as easily exploitable and can be triggered by an unauthenticated attacker with network access via HTTP. While specific technical details regarding the vulnerability class (e.g., SQLi or Broken Access Control) are not explicitly named, the impact includes unauthorized read, update, insert, or delete access to a subset of system data. Notably, the vulnerability carries a 'Scope Change' (S:C) designation, indicating that an exploit can impact components or products beyond the immediate security scope of the affected software. Affected versions include various releases across the 2.5.x, 2.6.x, and 25.12.x branches.
Affected products
- Oracle Utilities Network Management System 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, 25.12.0.0.0-25.12.0.0.2
Timeline
- 2026-07-21: advisory: Oracle released the July 2026 Critical Patch Update containing this vulnerability.
- 2026-07-21: disclosed