CVE-2026-61126: Oracle Communications Billing And Revenue Management

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform). Supported versions that are affected are 15.0.0.0.0-15.0.1.0.0 and 15.1.0.0.0-15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Billing and Revenue Management executes to compromise Oracle Communications Billing and Revenue Management. Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Affected products

  • Oracle Communications Billing And Revenue Management: from 15.0.0.0.0, up to and including 15.0.1.0.0; from 15.1.0.0.0, up to and including 15.2.0.0.0

Published 2026-07-21. Last modified 2026-08-17.