CVE-2026-61091: High severity Oracle Communications Oracle Communications Billing and Revenue Management vulnerability
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: BRM Server). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Billing and Revenue Management executes to compromise Oracle Communications Billing and Revenue Management. Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Communications Billing and Revenue Management (BRM Server)to a version that resolves this vulnerability.Fixed in 15.2.0.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61091?
The severity of CVE-2026-61091 is classified as high with a score of 7.8.
How do I fix CVE-2026-61091?
To fix CVE-2026-61091, it is recommended to update the Oracle Communications Billing and Revenue Management product to a patched version.
Which versions are affected by CVE-2026-61091?
The affected versions of CVE-2026-61091 are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, and 15.2.0.0.0.
What type of attackers can exploit CVE-2026-61091?
CVE-2026-61091 can be exploited by low privileged attackers with logon access.
What impact does CVE-2026-61091 have on data integrity?
CVE-2026-61091 has a high impact on confidentiality, integrity, and availability of the system.