PatchSiren cyber security CVE debrief
CVE-2026-46981 Oracle CVE debrief
The CVE-2026-46981 vulnerability affects Oracle Utilities Network Management System, specifically in the Mobile component. This vulnerability allows unauthenticated attackers with network access via HTTP to compromise the system. The affected versions are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, and 25.12.0.0.0-25.12.0.0.2. Successful attacks can result in unauthorized update, insert or delete access to some accessible data as well as unauthorized read access to a subset of accessible data. The CVSS score is 7.2 with HIGH severity.
- Vendor
- Oracle
- Product
- Utilities Network Management System
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-08-06
Who should care
Organizations using Oracle Utilities Network Management System, especially those with versions 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, and 25.12.0.0.0-25.12.0.0.2, should prioritize patching and focus on verifying system configurations, monitoring for suspicious activity, and implementing compensating controls for exposed systems.
Technical summary
CVE-2026-46981 is a vulnerability in Oracle Utilities Network Management System, allowing unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized update, insert or delete access to some accessible data as well as unauthorized read access to a subset of accessible data. The vulnerability has a CVSS score of 7.2 and HIGH severity. The affected versions are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, and 25.12.0.0.0-25.12.0.0.2.
Defensive priority
Organizations using Oracle Utilities Network Management System should prioritize patching, focusing on the affected versions 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, and 25.12.0.0.0-25.12.0.0.2.
Recommended defensive actions
- Apply patches for affected Oracle Utilities Network Management System versions
- Restrict network access to the system
- Monitor for suspicious activity
- Inventory and verify system configurations
- Implement compensating controls for exposed systems
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE-2026-46981 vulnerability affects Oracle Utilities Network Management System, with CVSS score of 7.2 and HIGH severity. Supported versions that are affected are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, and 25.12.0.0.0-25.12.0.0.2. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System. While the vulnerability is in Oracle Utilities Network Management System, attacks may significantly impact additional products (scope change).
Official resources
-
CVE-2026-46981 CVE record
CVE.org
-
CVE-2026-46981 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:03.123Z and has not been modified since then.