Junglewise Threat Intelligence

CVE-2026-83417: Oracle Communications Cloud Native Core Security Edge Protection Proxy physical access vulnerability

CVE-2026-83417 · Severity: high · CVSS 7.1 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Communications Cloud Native Core Security Edge Protection Proxy is a security appliance that protects carrier network infrastructure. An unauthenticated attacker with physical access to the network segment connected to the device can read sensitive data or modify network traffic and configurations without any authentication, potentially exposing carrier customer data or disrupting service delivery.

Technical details

This vulnerability in Oracle Communications Cloud Native Core Security Edge Protection Proxy (versions 26.1.200 and 25.2.201) allows unauthenticated attackers with physical access to the adjacent network segment to gain unauthorized access to critical data and modify stored information. The attack requires proximity to the physical communication segment but no authentication credentials or user interaction. Successful exploitation results in confidentiality and integrity compromise—specifically, full read access to sensitive data and limited write access to configuration or stored data. Patches are expected to be available through Oracle's security advisory channels.

Affected products

  • Oracle Cloud Native Core Security Edge Protection Proxy 26.1.200, 25.2.201

Timeline

  • 2026-09-15: disclosed

References