Security Flaw in Oracle Communications Converged Application Server
CVE-2026-61223

9CRITICAL

What is CVE-2026-61223?

A security vulnerability has been identified in the Oracle Communications Converged Application Server that can be exploited by an unauthenticated attacker with network access via TCP/IP. The flaw exists in the server's security component, which could allow unauthorized access and compromise of the system. While the main target is the Converged Application Server, the potential impact may extend to other associated products, emphasizing the severity of this vulnerability. Versions 8.2 and 8.3 are notably affected, leading to possible takeover scenarios that compromise confidentiality, integrity, and availability of services.

Affected Version(s)

Oracle Communications Converged Application Server 8.2

Oracle Communications Converged Application Server 8.3

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.