ZeroHour

CVE-2026-83342

niche

Local Privilege Escalation in Oracle Utilities Network Management System

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

A high-severity vulnerability (CVSS 3.1 base score 7.8) in the System Wide component of Oracle Utilities Network Management System (OUNMS) allows a low-privileged attacker who already has logon access to the host where OUNMS executes to escalate privileges and take over the entire product. The flaw is described by Oracle as easily exploitable via the local attack vector with no user interaction required, and successful attacks compromise confidentiality, integrity, and availability of the NMS. All supported release lines are affected, spanning versions 2.4.0.1.x through 2.6.0.2.x and the 25.12.0.0.x line. Because exploitation requires pre-existing local access to the NMS infrastructure, the realistic threat is from malicious or compromised insiders, lateral movement after an initial host compromise, or misuse by over-privileged service accounts rather than remote internet-based attackers. No public proof of concept exists, the CVE is not in the CISA Known Exploited Vulnerabilities catalog, and no exploitation in the wild is known at this time.

What to do: Apply the Oracle Critical Patch Update remediation for this CVE on every affected OUNMS instance and verify that no servers remain on the listed affected version ranges. Since the attack requires local logon to the NMS host, restrict OS-level accounts on those servers to the minimum necessary, enforce least privilege for service accounts, and audit local authentication and privilege-escalation events. If unauthorized local account activity is suspected, rotate credentials on the NMS hosts and review for follow-on compromise of the system.

Affected
Oracle Utilities Network Management System (component: System Wide)2.4.0.1.0-2.4.0.1.33
Oracle Utilities Network Management System (component: System Wide)2.5.0.1.0-2.5.0.1.19
Oracle Utilities Network Management System (component: System Wide)2.5.0.2.0-2.5.0.2.13
Oracle Utilities Network Management System (component: System Wide)2.6.0.1.0-2.6.0.12B
Oracle Utilities Network Management System (component: System Wide)2.6.0.2.0-2.6.0.2.10A
Oracle Utilities Network Management System (component: System Wide)25.12.0.0.0-25.12.0.0.3
Estimated exposure
nichelikely on the order of a few hundred to low thousands of utility NMS installations worldwide — Oracle Utilities NMS is licensed enterprise control-center software deployed by electric, gas, and water utilities with no public install counts, and typical deployment is a small number of instances per utility, implying a global install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide). Supported versions that are affected are 2.4.0.1.0-2.4.0.1.33, 2.5.0.1.0-2.5.0.1.19, 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A and 25.12.0.0.0-25.12.0.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Utilities Network Management System executes to compromise Oracle Utilities Network Management System. Successful attacks of this vulnerability can result in takeover of Oracle Utilities Network Management System. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.