PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46981 Oracle CVE debrief

The CVE-2026-46981 vulnerability affects Oracle Utilities Network Management System, specifically in the Mobile component. This vulnerability allows unauthenticated attackers with network access via HTTP to compromise the system. The affected versions are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, and 25.12.0.0.0-25.12.0.0.2. Successful attacks can result in unauthorized update, insert or delete access to some accessible data as well as unauthorized read access to a subset of accessible data. The CVSS score is 7.2 with HIGH severity.

Vendor
Oracle
Product
Utilities Network Management System
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-08-06
Advisory published
2026-07-21
Advisory updated
2026-08-06

Who should care

Organizations using Oracle Utilities Network Management System, especially those with versions 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, and 25.12.0.0.0-25.12.0.0.2, should prioritize patching and focus on verifying system configurations, monitoring for suspicious activity, and implementing compensating controls for exposed systems.

Technical summary

CVE-2026-46981 is a vulnerability in Oracle Utilities Network Management System, allowing unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized update, insert or delete access to some accessible data as well as unauthorized read access to a subset of accessible data. The vulnerability has a CVSS score of 7.2 and HIGH severity. The affected versions are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, and 25.12.0.0.0-25.12.0.0.2.

Defensive priority

Organizations using Oracle Utilities Network Management System should prioritize patching, focusing on the affected versions 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, and 25.12.0.0.0-25.12.0.0.2.

Recommended defensive actions

  • Apply patches for affected Oracle Utilities Network Management System versions
  • Restrict network access to the system
  • Monitor for suspicious activity
  • Inventory and verify system configurations
  • Implement compensating controls for exposed systems
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE-2026-46981 vulnerability affects Oracle Utilities Network Management System, with CVSS score of 7.2 and HIGH severity. Supported versions that are affected are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, and 25.12.0.0.0-25.12.0.0.2. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System. While the vulnerability is in Oracle Utilities Network Management System, attacks may significantly impact additional products (scope change).

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:03.123Z and has not been modified since then.