Junglewise Threat Intelligence

CVE-2026-61143: Oracle Communications Convergent Charging Controller compromise in Prov IF

CVE-2026-61143 · Severity: medium · CVSS 6.4 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Communications Convergent Charging Controller, a system used by telecommunications providers to manage real-time billing and charging for services. A highly privileged attacker could potentially take full control of the system, which could lead to service disruptions or unauthorized changes to customer billing data. Exploiting this flaw is considered difficult as it requires the attacker to trick a legitimate user into performing a specific action.

Technical details

This vulnerability affects the Prov IF component of Oracle Communications Convergent Charging Controller versions 15.0.0.0.0 and 15.2.0.0.0. It is classified as a difficult-to-exploit flaw that requires a high-privileged attacker to have network access via HTTP. A successful exploit requires human interaction from a user other than the attacker (UI:R). If successful, the attacker can achieve a complete takeover of the affected product, impacting confidentiality, integrity, and availability. The vulnerability was disclosed as part of the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Communications Convergent Charging Controller 15.0.0.0.0, 15.2.0.0.0

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-61143

References