CVE-2026-83343
nicheUnauthenticated HTTP Data-Access Flaw in Oracle Utilities Network Management System
CVE-2026-83343 is a vulnerability in the System Wide component of Oracle Utilities Network Management System (OUNMS), part of Oracle Utilities Applications, rated High with a CVSS 3.1 base score of 8.2. An unauthenticated attacker with network access via HTTP can exploit the flaw easily and without user interaction, gaining unauthorized read access to critical data or all OUNMS-accessible data, as well as unauthorized update, insert, and delete access to some of that data (confidentiality high, integrity low, no availability impact). The affected deployments are utility organizations running OUNMS versions 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A, or 25.12.0.0.0-25.12.0.0.3. Because OUNMS is typically deployed inside utility operations networks and is not broadly internet-exposed, the attack surface is concentrated but high-value (grid/outage and customer operational data). No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild is known as of this analysis.
What to do: Apply Oracle's Critical Patch Update remediation for CVE-2026-83343 to all OUNMS instances on versions 2.5.0.2.x, 2.6.0.1.x/2.6.0.2.x, and 25.12.0.0.x as soon as the fix is available. Restrict HTTP access to OUNMS endpoints to trusted internal networks, management VPNs, or allowlisted IPs, since the flaw requires no authentication and is rated easily exploitable. Review logs for anomalous unauthenticated data reads or unexpected update/insert/delete activity against OUNMS data going back to patch deployment.
| Oracle Utilities Network Management System (Oracle Utilities Applications) | 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A, 25.12.0.0.0-25.12.0.0.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide). Supported versions that are affected are 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A and 25.12.0.0.0-25.12.0.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Utilities Network Management System accessible data as well as unauthorized update, insert or delete access to some of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.