Executive brief
Oracle Communications Cloud Native Core Security Edge Protection Proxy (SEPP) is a security component that protects telecommunications network traffic and services. A vulnerability allows low-privileged attackers with network access to read sensitive data and make unauthorized changes to stored information, potentially compromising the integrity of telecommunications services and exposing customer or operational data.
Technical details
This vulnerability in the SEPP component is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise the service. The attack requires authentication (low privilege account) and no user interaction. Successful exploitation results in both unauthorized read access to a subset of accessible data and unauthorized create, update, or delete operations on certain data resources. The vulnerability affects versions 26.1.200 and 25.2.201 of the product.
Affected products
- Oracle Communications Cloud Native Core Security Edge Protection Proxy 26.1.200, 25.2.201
Timeline
- 2026-09-15: disclosed