Executive brief
Oracle Utilities Network Management System is a critical infrastructure management platform used by utility companies to manage power, water, and gas networks. A local privilege escalation vulnerability allows a low-privileged employee or contractor with system access to gain complete control of the application, potentially disrupting service operations, exposing customer data, or compromising grid management capabilities.
Technical details
This is a local privilege escalation vulnerability in Oracle Utilities Network Management System's core system components. The vulnerability is easily exploitable and requires only local logon access (low privilege user) with no additional user interaction needed. Successful exploitation grants an attacker complete control over the application, allowing compromise of confidentiality, integrity, and availability of the system. Attack vector is local (AV:L), attack complexity is low (AC:L), and low privilege (PR:L) is sufficient. No patch or workaround details are currently available from the provided advisory.
Affected products
- Oracle Utilities Network Management System 2.4.0.1.0–2.4.0.1.33, 2.5.0.1.0–2.5.0.1.19, 2.5.0.2.0–2.5.0.2.13, 2.6.0.1.0–2.6.0.12B, 2.6.0.2.0–2.6.0.2.10A, 25.12.0.0.0–25.12.0.0.3
Timeline
- 2026-09-15: disclosed