Executive brief
Oracle Communications Unified Inventory Management, a platform used by telecommunications providers to manage network assets and services, contains a security vulnerability. An attacker with basic user credentials can gain unauthorized access to sensitive business data over the network. This could lead to the theft of critical information or the unauthorized modification of inventory records, potentially disrupting service operations.
Technical details
A vulnerability exists in the Security component of Oracle Communications Unified Inventory Management versions 7.5.0 through 8.0.1. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows for unauthorized read access to critical data (High Confidentiality impact) and unauthorized update, insert, or delete access to a subset of data (Low Integrity impact). The attack does not require user interaction. Organizations should refer to the Oracle Critical Patch Update for July 2026 for remediation guidance.
Affected products
- Oracle Communications Unified Inventory Management 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0, 8.0.1
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle