Junglewise Threat Intelligence

CVE-2026-71142: Oracle Communications Unified Inventory Management authentication bypass

CVE-2026-71142 · Severity: high · CVSS 7.5 · Published 2026-08-18

Vendors: Oracle.

Executive brief

Oracle Communications Unified Inventory Management is a system used by telecommunications providers to track and manage communications infrastructure inventory. A vulnerability allows unauthenticated attackers on the network to bypass security controls via HTTP and gain unauthorized access to sensitive data stored within the system, potentially exposing critical operational and customer information.

Technical details

The vulnerability is an authentication bypass in the Security Component of Oracle Communications Unified Inventory Management that allows unauthenticated attackers to access critical data. The flaw can be exploited over the network via HTTP without requiring user interaction or special privileges. An attacker can achieve complete unauthorized access to all data accessible through the application. The vulnerability affects versions 7.5.0 through 7.5.1, 7.6.0 through 8.0.0, and 8.0.1. Patch availability is not confirmed in the available advisory references.

Affected products

  • Oracle Communications Unified Inventory Management 7.5.0-7.5.1, 7.6.0-8.0.0, 8.0.1

Timeline

  • 2026-08-18: disclosed

References

Related threats