Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspusep2026.html |
|
Thu, 24 Sep 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Sep 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low‑privileged HTTP Attack Enables Unauthorized Access to Oracle SEPP Data |
Tue, 22 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized data modification via HTTP in Oracle SEPP | |
| Weaknesses | CWE-285 |
Tue, 22 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 |
Sun, 20 Sep 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized data modification via HTTP in Oracle SEPP | |
| Weaknesses | CWE-285 |
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTP Access Allows Data Modification in Oracle SEPP | |
| Weaknesses | CWE-200 CWE-284 |
Wed, 16 Sep 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTP Access Allows Data Modification in Oracle SEPP | |
| Weaknesses | CWE-200 CWE-284 |
Tue, 15 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as unauthorized read access to a subset of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N). | |
| First Time appeared |
Oracle
Oracle communications Cloud Native Core Security Edge Protection Proxy |
|
| CPEs | cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:25.2.201:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:26.1.200:*:*:*:*:*:*:* |
|
| Vendors & Products |
Oracle
Oracle communications Cloud Native Core Security Edge Protection Proxy |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-09-22T14:46:04.106Z
Reserved: 2026-08-31T15:40:57.358Z
Link: CVE-2026-83419
Updated: 2026-09-22T14:45:48.153Z
Status : Awaiting Analysis
Published: 2026-09-15T20:18:50.343
Modified: 2026-09-22T15:17:18.187
Link: CVE-2026-83419
No data.
OpenCVE Enrichment
Updated: 2026-09-22T19:00:13Z