PatchSiren cyber security CVE debrief
CVE-2026-46981 Oracle CVE debrief
The CVE-2026-46981 vulnerability affects Oracle Utilities Network Management System, specifically in the Mobile component. This vulnerability allows unauthenticated attackers with network access via HTTP to compromise the system. The affected versions are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, and 25.12.0.0.0-25.12.0.0.2. Successful attacks can result in unauthorized update, insert or delete access to some accessible data as well as unauthorized read access to a subset of accessible data. The CVSS score is 7.2 with HIGH severity.
- Vendor
- Oracle
- Product
- Utilities Network Management System
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-08-06
Who should care
Organizations using Oracle Utilities Network Management System, especially those with versions 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, and 25.12.0.0.0-25.12.0.0.2, should prioritize patching and focus on verifying system configurations, monitoring for suspicious activity, and implementing compensating controls for exposed systems.
Technical summary
CVE-2026-46981 is a vulnerability in Oracle Utilities Network Management System, allowing unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized update, insert or delete access to some accessible data as well as unauthorized read access to a subset of accessible data. The vulnerability has a CVSS score of 7.2 and HIGH severity. The affected versions are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, and 25.12.0.0.0-25.12.0.0.2.
Defensive priority
Organizations using Oracle Utilities Network Management System should prioritize patching, focusing on the affected versions 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, and 25.12.0.0.0-25.12.0.0.2.
Recommended defensive actions
- Apply patches for affected Oracle Utilities Network Management System versions
- Restrict network access to the system
- Monitor for suspicious activity
- Inventory and verify system configurations
- Implement compensating controls for exposed systems
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE-2026-46981 vulnerability affects Oracle Utilities Network Management System, with CVSS score of 7.2 and HIGH severity. Supported versions that are affected are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, and 25.12.0.0.0-25.12.0.0.2. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System. While the vulnerability is in Oracle Utilities Network Management System, attacks may significantly impact additional products (scope change).
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46981 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46981
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46981 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46981
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cpujul2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.