Junglewise Threat Intelligence

CVE-2026-83342: Oracle Utilities Network Management System privilege escalation

CVE-2026-83342 · Severity: high · CVSS 7.8 · Published 2026-09-15

Technologies: Oracle Utilities Network Management System. Vendors: Oracle.

Executive brief

Oracle Utilities Network Management System is a critical infrastructure management platform used by utility companies to manage power, water, and gas networks. A local privilege escalation vulnerability allows a low-privileged employee or contractor with system access to gain complete control of the application, potentially disrupting service operations, exposing customer data, or compromising grid management capabilities.

Technical details

This is a local privilege escalation vulnerability in Oracle Utilities Network Management System's core system components. The vulnerability is easily exploitable and requires only local logon access (low privilege user) with no additional user interaction needed. Successful exploitation grants an attacker complete control over the application, allowing compromise of confidentiality, integrity, and availability of the system. Attack vector is local (AV:L), attack complexity is low (AC:L), and low privilege (PR:L) is sufficient. No patch or workaround details are currently available from the provided advisory.

Affected products

  • Oracle Utilities Network Management System 2.4.0.1.0–2.4.0.1.33, 2.5.0.1.0–2.5.0.1.19, 2.5.0.2.0–2.5.0.2.13, 2.6.0.1.0–2.6.0.12B, 2.6.0.2.0–2.6.0.2.10A, 25.12.0.0.0–25.12.0.0.3

Timeline

  • 2026-09-15: disclosed

References

Related threats