Junglewise Threat Intelligence

CVE-2026-61127: Oracle Communications Service Catalog and Design takeover in Solution Designer

CVE-2026-61127 · Severity: high · CVSS 8.8 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle's software used for managing telecommunications service catalogs and designs. An attacker with basic user access can exploit this flaw over the network to gain full control of the system. This could lead to the unauthorized modification of service designs, theft of sensitive configuration data, or a total disruption of the service management platform.

Technical details

A vulnerability in the Solution Designer component of Oracle Communications Service Catalog and Design (versions 8.0.0.7.0 through 8.3.0.2.0) allows for a complete system takeover. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation grants the attacker full control over the confidentiality, integrity, and availability of the affected component. While the specific CWE is not listed in the advisory, the impact and vector suggest a significant authorization or injection-related bypass. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Communications Service Catalog and Design 8.0.0.7.0 - 8.3.0.2.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle via July 2026 CPU
  • 2026-07-21: advisory: NVD publication date

References