Sceawere

Vulnerability Detail

CVE-2026-71143UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Communications UIM Authorization Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.4
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Communications Unified Inventory Management
Attack Type
Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Inventory Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data.
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Third Party). Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0-7.8.0 and 8.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Inventory Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.4",
  "pubDate": "2026-08-18T21:18:15.253Z",
  "pubdate": "2026-08-18T21:18:15.253Z",
  "executiveSummary": "An authorization and data access vulnerability exists within the Third Party component of the Oracle Communications Unified Inventory Management product. Supported versions affected by this flaw include 7.5.0, 7.5.1, 7.6.0-7.8.0, and 8.0.1. This security issue is categorized as difficult to exploit, requiring specific conditions, yet it grants significant unauthorized capabilities to malicious actors. An unauthenticated attacker leveraging network access via HTTP can successfully exploit this vulnerability to compromise the integrity and confidentiality of the targeted system. Specifically, successful exploitation leads to unauthorized creation, deletion, or modification of critical data or all accessible data within Oracle Communications Unified Inventory Management, alongside unauthorized access to critical or complete data sets. The associated CVSS 3.1 base score is 7.4 with high impacts to confidentiality and integrity, while availability remains unaffected. The attack vector is network-based with no user interaction or privileges required, though the attack complexity is rated as high. Organizations utilizing the specified vulnerable versions face severe risk regarding data exposure and unauthorized data manipulation, necessitating prompt defensive evaluations and implementation of vendor-supplied patches or compensating controls.",
  "technicalDetails": "The vulnerability resides in the Third Party component of Oracle Communications Unified Inventory Management across versions 7.5.0, 7.5.1, 7.6.0-7.8.0, and 8.0.1. The root cause stems from insufficient access controls, improper authorization validation, or boundary enforcement mechanisms within the affected component when processing incoming HTTP requests. The vulnerability allows unauthenticated network-based entities to bypass intended security perimeters and interact directly with sensitive application logic or data stores. Because the attack vector is network-based (AV:N), adversaries do not require local access, physical presence, or prior execution rights on the host infrastructure. Furthermore, the attack requires no user interaction (UI:N) and demands zero privileges (PR:N), meaning any external entity capable of establishing an HTTP connection to the service can theoretically initiate the exploit chain. The attack complexity is evaluated as high (AC:H), implying that successful exploitation requires specific preconditions, precise timing, non-standard configurations, or specialized payload structuring to successfully bypass existing defensive controls within the Third Party component. During the attack flow, the malicious actor transmits crafted HTTP requests targeting vulnerable endpoints exposed by the Third Party component. Due to inadequate input validation or improper session and authorization checks, the application processes the request without verifying whether the source possesses the requisite authorization credentials. Post-exploitation impact is severe, granting the attacker the capability to execute unauthorized data modification, creation, and deletion operations against critical or complete datasets managed by Oracle Communications Unified Inventory Management. Additionally, the attacker achieves unauthorized read access to critical and complete data repositories, leading to a total compromise of data confidentiality and integrity within the application scope, while the availability vector remains unimpacted (A:N)."
}
CVE-2026-71143: Oracle Communications UIM Authorization Vulnerability (HIGH Severity, CVSS: 7.4) - Sceawere