Junglewise Threat Intelligence

CVE-2026-83343: Oracle Utilities Network Management System unauthenticated access vulnerability

CVE-2026-83343 · Severity: high · CVSS 8.2 · Published 2026-09-15

Technologies: Oracle Utilities Network Management System. Vendors: Oracle.

Executive brief

Oracle Utilities Network Management System is a critical component used by utilities companies to manage network infrastructure and operations. This vulnerability allows an unauthenticated attacker to remotely access the system over the network, potentially exposing sensitive operational data, customer information, and enabling unauthorized modifications to system records—creating significant business disruption and regulatory compliance risks for utility operators.

Technical details

The vulnerability is an easily exploitable, unauthenticated remote access flaw in Oracle Utilities Network Management System accessible via HTTP (network attack vector). No authentication, user interaction, or complex configuration is required for exploitation. Successful attacks grant unauthorized read access to critical data and modification (update/insert/delete) capabilities over a subset of accessible data. The flaw resides in the System Wide component. Affected versions include 2.5.0.2.0–2.5.0.2.13, 2.6.0.1.0–2.6.0.12B, 2.6.0.2.0–2.6.0.2.10A, and 25.12.0.0.0–25.12.0.0.3; patched versions should be available from Oracle.

Affected products

  • Oracle Utilities Network Management System 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A, 25.12.0.0.0-25.12.0.0.3

Timeline

  • 2026-09-15: disclosed
  • other: Reported not exploited in the wild as of publication date

References

Related threats