Junglewise Threat Intelligence

CVE-2026-61091: Oracle Communications Billing and Revenue Management takeover in BRM Server

CVE-2026-61091 · Severity: high · CVSS 7.8 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability in the Oracle Communications Billing and Revenue Management (BRM) Server could allow an unauthorized individual to take full control of the system. This software is used by telecommunications companies to manage customer billing, subscriptions, and revenue. An attacker who already has basic access to the underlying server infrastructure could exploit this flaw to access sensitive financial data, disrupt billing operations, or modify service records.

Technical details

A vulnerability exists in the BRM Server component of Oracle Communications Billing and Revenue Management versions 15.0.0.0.0 through 15.2.0.0.0. The flaw is categorized as easily exploitable and requires the attacker to have local logon access to the infrastructure where the BRM software is executing. Successful exploitation allows a low-privileged user to achieve a complete takeover of the application, impacting confidentiality, integrity, and availability. The attack vector is local (AV:L) with low complexity (AC:L) and requires no user interaction (UI:N). Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Communications Billing and Revenue Management 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, 15.2.0.0.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD record published

References