Junglewise Threat Intelligence

CVE-2026-61053: Oracle Communications BRM Elastic Charging Engine takeover in Diameter Gateway

CVE-2026-61053 · Severity: high · CVSS 7.8 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle's billing and revenue management software, specifically within the component responsible for real-time charging and network communication. An attacker who already has basic access to the server where this software is running could exploit this flaw to take full control of the charging engine. This could lead to unauthorized manipulation of billing data, service disruptions, or the theft of sensitive customer information.

Technical details

This vulnerability affects the Diameter Gateway and SDK components of Oracle Communications BRM - Elastic Charging Engine. It is classified as a local exploit, requiring the attacker to have existing logon credentials to the underlying infrastructure where the application resides. The flaw is described as easily exploitable and does not require user interaction. A successful exploit allows a low-privileged user to achieve a complete compromise of the application, impacting confidentiality, integrity, and availability. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Communications BRM - Elastic Charging Engine 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, 15.2.0.0.0

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this vulnerability.
  • 2026-07-21: disclosed: NVD published the CVE record.

References