Junglewise Threat Intelligence

CVE-2026-83418: Oracle Communications Cloud Native Core Security Edge Protection Proxy authentication bypass

CVE-2026-83418 · Severity: high · CVSS 8.2 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Communications Cloud Native Core Security Edge Protection Proxy (SEPP) is a network security component used to protect telecommunications infrastructure in cloud deployments. A flaw in this product allows an authenticated attacker with network access to bypass security controls and gain unauthorized access to critical data, potentially compromising sensitive information or allowing malicious modifications that could impact dependent systems.

Technical details

The vulnerability exists in Oracle Communications Cloud Native Core Security Edge Protection Proxy versions 26.1.200 and 25.2.201. It is a difficult-to-exploit flaw accessible via HTTP that requires low-level privileges and network connectivity. The attack has a changed scope (S:C), indicating that successful exploitation can impact systems beyond the directly vulnerable component. An attacker can achieve unauthorized creation, deletion, or modification of critical data, or gain complete read access to all data managed by the SEPP component. No public exploit is known to be in active use.

Affected products

  • Oracle Communications Cloud Native Core Security Edge Protection Proxy 26.1.200, 25.2.201

Timeline

  • 2026-09-15: disclosed

References

Related threats