ZeroHour

CVE-2026-83418

niche

Privilege Escalation in Oracle Cloud Native Core SEPP 5G Roaming Proxy

CVSS 3.1
8.2 high
EPSS
Published
()
Modified
AI analysis

An improper-authorization vulnerability in Oracle Communications Cloud Native Core Security Edge Protection Proxy (SEPP) — the 5G network element that secures inter-operator roaming traffic on the N32 interface — allows a low-privileged attacker with network access via HTTP to fully compromise the proxy. Exploitation is rated difficult (attack complexity high), but a successful attack grants unauthorized creation, deletion, or modification of, and complete read access to, all SEPP-accessible data, and the scope change means other products beyond SEPP in the operator's environment can be significantly impacted as well. Affected releases are 26.1.200 and 25.2.201, so telecom operators running Oracle's cloud-native 5G core with roaming interconnect are the affected population. No public proof of concept is known and the flaw is not on CISA's KEV, so there is no indication of exploitation in the wild.

What to do: Apply Oracle's latest Critical Patch Update to move off affected releases 26.1.200 and 25.2.201 as soon as the fixed version is available. Restrict HTTP network access to the SEPP to trusted roaming partners and internal management segments, enforce mutual TLS and strong authentication on N32 and management interfaces, and review or revoke unnecessary low-privileged accounts. Audit SEPP logs for unexpected data creation, modification, or access and watch for lateral impact on adjacent 5G core components given the scope change.

Affected
Oracle Communications Cloud Native Core Security Edge Protection Proxy (SEPP)26.1.200, 25.2.201
Estimated exposure
nichelikely tens to low hundreds of carrier installations worldwide (exact count unknown) — SEPP is specialized carrier-grade 5G core equipment deployed only by mobile network operators, there are only roughly 1,000+ MNOs globally, and Oracle is one of several 5G core vendors, so the affected footprint is limited to operators…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. While the vulnerability is in Oracle Communications Cloud Native Core Security Edge Protection Proxy, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.