CVE-2026-71142: High severity Oracle Communications Oracle Communications Unified Inventory Management vulnerability
Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component). Supported versions that are affected are 7.5.0-7.5.1, 7.6.0-7.8.0 and 8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Communications Unified Inventory Management (Security Component)to a version that resolves this vulnerability.Fixed in 7.5.0-7.5.1 - Upgrade
Upgrade
Oracle Communications Unified Inventory Management (Security Component)to a version that resolves this vulnerability.Fixed in 7.6.0-7.8.0 - Upgrade
Upgrade
Oracle Communications Unified Inventory Management (Security Component)to a version that resolves this vulnerability.Fixed in 8.0.1
Event History
Frequently Asked Questions
Which deployments are affected?
Affected supported versions are 7.5.0 through 7.5.1, 7.6.0 through 7.8.0, and 8.0.1 of Oracle Communications Unified Inventory Management. The issue is in the Security Component.
Does exploitation require an account or user interaction?
No. An unauthenticated attacker can exploit the vulnerability over HTTP with network access, and no user interaction is required.
What is the likely impact of successful exploitation?
Successful exploitation can provide unauthorized access to critical data or complete access to all data accessible through Oracle Communications Unified Inventory Management. The stated impact is confidentiality only; integrity and availability impacts are not identified.