Junglewise Threat Intelligence

CVE-2026-47007: Oracle Communications Pricing Design Center data compromise in On-premise Deployment

CVE-2026-47007 · Severity: high · CVSS 7.3 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle Communications Pricing Design Center, a tool used by telecommunications companies to manage product pricing and rating, contains a security vulnerability in its on-premise deployment component. An attacker who already has basic access to the server where the software is installed could exploit this flaw to gain unauthorized access to sensitive pricing data. This could lead to the theft of critical business information or the unauthorized modification of pricing records, potentially impacting other integrated business systems.

Technical details

A vulnerability exists in the On-premise Deployment component of Oracle Communications Pricing Design Center (versions 15.0.0.0.0 through 15.2.0.0.0). The flaw is easily exploitable by a low-privileged attacker with local logon access to the underlying infrastructure. Successful exploitation results in a scope change (S:C), allowing the attacker to gain unauthorized read access to critical data and limited write/delete access to system information. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Communications Pricing Design Center 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, 15.2.0.0.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References