← Vulnerability feed

Vulnerability record · CVE-2026-61223 · published 21 July 2026

CVE-2026-61223: Oracle communications converged application server improper access control vulnerability

Oracle · Communications Converged Application Server

Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). Supported versions that are affected are 8.2 and 8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications Converged Application Server. While the vulnerability is in Oracle Communications Converged Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).

9.0 CVSS 3.1 Critical EPSS 0.39% · top 69.2% CWE-284 · Improper access control
9.0CVSS 3.1 base score
0.39%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
6 Aug 2026Last modified by NVD

Description

Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). Supported versions that are affected are 8.2 and 8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications Converged Application Server. While the vulnerability is in Oracle Communications Converged Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-61223 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-2725Oracle WebLogic Server Web Services deserialization RCEOracle WebLogic Server's Web Services subcomponent contains an injection flaw (CWE-74) that allows unauthenticated remote code execution over HTTP. I…KEVEPSS 100%analysed9.8CVE-2023-21890Oracle communications converged application server code injection vulnerabilityVulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that a…EPSS 0.84%9.8CVE-2018-1000613Bouncycastle bc-java vulnerabilityLegion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externall…EPSS 4.8%9.8CVE-2018-1275Spring Framework STOMP over WebSocket broker message code injectionSpring Framework 5.0 before 5.0.5 and 4.3 before 4.3.16 let applications expose STOMP over WebSocket endpoints backed by a simple in-memory STOMP bro…EPSS 57%analysed9.8CVE-2018-1270Spring Framework STOMP over WebSocket broker remote code executionSpring Framework versions 5.0 before 5.0.5 and 4.3 before 4.3.15 (plus older unsupported versions) allow applications to expose STOMP over WebSocket …EPSS 77%analysed8.8CVE-2018-1258Pivotal software spring security incorrect authorization vulnerabilitySpring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method secur…EPSS 2.5%8.1CVE-2026-61225Oracle communications converged application server improper privilege management vulnerabilityVulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that a…EPSS 0.39%8.0CVE-2026-61224Oracle communications converged application server improper access control vulnerabilityVulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). The supported version…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2026-61223), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.