CVE-2026-83417
nicheUnauthenticated Adjacent-Network Data Access Flaw in Oracle Cloud Native Core SEPP
CVE-2026-83417 is an unauthenticated vulnerability in the Security Edge Protection Proxy (SEPP) component of Oracle Communications Cloud Native Core, affecting versions 26.1.200 and 25.2.201. An attacker who can reach the physical communication segment attached to the hardware where the SEPP executes — i.e., a local/adjacent-network position such as a compromised host or tapped interconnect link in the operator's network or roaming exchange — can exploit the flaw with low complexity and no credentials or user interaction. A successful attack can expose critical data or all SEPP-accessible data and allow unauthorized update, insert, or delete access to some of that data, though availability is not impacted (CVSS 3.1: 7.1, AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N). Because the SEPP secures inter-operator 5G roaming signaling (N32), compromised data likely includes roaming signaling traffic between the home network and roaming partners. No public proof-of-concept or known in-the-wild exploitation has been reported, and the CVE is not on the CISA KEV list.
What to do: Apply Oracle's Critical Patch Update remediation for CVE-2026-83417 to SEPP deployments running 26.1.200 or 25.2.201 as soon as the fix is available. Restrict the network segments reachable by SEPP nodes with strict ACLs and segmentation so only trusted core elements and authenticated roaming-partner/IPX endpoints can communicate with it. Review SEPP and IPX-edge logs for anomalous N32 signaling, unexpected data queries, or unauthorized modifications originating from interconnect segments.
| Oracle Communications Cloud Native Core Security Edge Protection Proxy (SEPP) | 26.1.200, 25.2.201 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Communications Cloud Native Core Security Edge Protection Proxy executes to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.