Junglewise Threat Intelligence

CVE-2026-61226: Oracle Communications Converged Application Server takeover in RTP Proxy

CVE-2026-61226 · Severity: high · CVSS 7.5 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A security vulnerability exists in the RTP Proxy component of Oracle Communications Converged Application Server, a platform used by telecommunications providers to manage multimedia sessions. A highly privileged attacker with existing access to the underlying server infrastructure could exploit this flaw to take full control of the application. Such an attack could lead to a complete loss of data confidentiality and service availability, potentially impacting other integrated systems.

Technical details

A vulnerability in the RTP Proxy component of Oracle Communications Converged Application Server version 8.3 allows for a complete system takeover. The flaw is characterized by a 'Scope Change' (S:C), meaning an exploit can impact components beyond the immediate security scope of the application. Exploitation is considered difficult (AC:H) and requires the attacker to already possess high-level privileges (PR:H) and local logon access to the infrastructure where the server executes. Successful exploitation results in a total compromise of confidentiality, integrity, and availability. The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle Communications Converged Application Server 8.3

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References