CVE-2026-61224: High severity Oracle Communications Oracle Communications Converged Application Server vulnerability
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with network access via TLS to compromise Oracle Communications Converged Application Server. While the vulnerability is in Oracle Communications Converged Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61224?
The severity of CVE-2026-61224 is classified as high with a score of 8.
How do I fix CVE-2026-61224?
To fix CVE-2026-61224, upgrade to the latest version of Oracle Communications Converged Application Server.
What products are affected by CVE-2026-61224?
CVE-2026-61224 affects the Oracle Communications Converged Application Server version 8.3.
What type of attackers can exploit CVE-2026-61224?
CVE-2026-61224 can be exploited by high privileged attackers with network access via TLS.
What impact does CVE-2026-61224 have on a system?
CVE-2026-61224 can lead to a complete compromise of the affected Oracle Communications system.