{
  "cve": "CVE-2026-83342",
  "enrichment": {
    "affected": [
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "[2.4.0.1.0,2.4.0.1.33]"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "[2.5.0.1.0,2.5.0.1.19]"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "[2.5.0.2.0,2.5.0.2.13]"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "[2.6.0.1.0,2.6.0.12B]"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "[2.6.0.2.0,2.6.0.2.10A]"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "[25.12.0.0.0,25.12.0.0.3]"
            }
          }
        ],
        "enrichment": {
          "confidence": 95.0,
          "confidence_source": "inferred",
          "scores": [
            {
              "score": 95.0,
              "source": "inferred"
            },
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "original": {
          "product": "Oracle Utilities Network Management System",
          "source": "cna",
          "vendor": "Oracle Corporation"
        },
        "product": "utilities_network_management_system",
        "vendor": "oracle"
      }
    ],
    "created": "2026-09-16T05:45:15.834938+00:00",
    "title": "Low‑Privileged Takeover in Oracle Utilities Network Management System",
    "updated": "2026-09-20T07:45:16.279253+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$utilities_network_management_system"
    ]
  },
  "epss": {
    "score": 0.00113
  },
  "mitre": {
    "cpes": [
      "cpe:2.3:a:oracle:utilities_network_management_system:*:*:*:*:*:*:*:*"
    ],
    "created": "2026-09-15T20:05:21.484000+00:00",
    "description": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide).  Supported versions that are affected are 2.4.0.1.0-2.4.0.1.33, 2.5.0.1.0-2.5.0.1.19, 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A and  25.12.0.0.0-25.12.0.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Utilities Network Management System executes to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Network Management System. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 7.8,
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/83xxx/CVE-2026-83342.json",
    "references": [
      "https://www.oracle.com/security-alerts/cspusep2026.html"
    ],
    "title": null,
    "updated": "2026-09-17T12:50:10.464000+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$utilities_network_management_system"
    ],
    "weaknesses": []
  },
  "nvd": {
    "cpes": [],
    "created": "2026-09-15T20:18:47.580000+00:00",
    "description": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide).  Supported versions that are affected are 2.4.0.1.0-2.4.0.1.33, 2.5.0.1.0-2.5.0.1.19, 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A and  25.12.0.0.0-25.12.0.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Utilities Network Management System executes to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Network Management System. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 7.8,
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-83342.json",
    "references": [
      "https://www.oracle.com/security-alerts/cspusep2026.html"
    ],
    "title": null,
    "updated": "2026-09-17T13:16:49.290000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-269"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-09-15T20:15:00+00:00",
        "data": [
          {
            "details": {
              "new": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide).  Supported versions that are affected are 2.4.0.1.0-2.4.0.1.33, 2.5.0.1.0-2.5.0.1.19, 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A and  25.12.0.0.0-25.12.0.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Utilities Network Management System executes to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Network Management System. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
              "old": null
            },
            "type": "description"
          },
          {
            "details": [
              "oracle",
              "oracle$PRODUCT$utilities_network_management_system"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:oracle:utilities_network_management_system:*:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "oracle",
                "oracle$PRODUCT$utilities_network_management_system"
              ],
              "removed": []
            },
            "type": "vendors"
          },
          {
            "details": {
              "added": [
                "https://www.oracle.com/security-alerts/cspusep2026.html"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 7.8,
                  "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "a1dba101-7b9d-4311-9f62-1703404cbfcd"
      },
      {
        "created": "2026-09-16T18:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "Local Privileged Attack Allows System Takeover in Oracle Utilities Network Management System",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-269",
                "CWE-284"
              ],
              "removed": []
            },
            "type": "weaknesses"
          }
        ],
        "id": "ff997629-2064-4f50-a382-af472fcab9a3"
      },
      {
        "created": "2026-09-17T14:30:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "no",
                    "Exploitation": "none",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "b977ffc9-d84f-4437-8ef2-088e9728a935"
      },
      {
        "created": "2026-09-18T15:45:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Local Privileged Attack Allows System Takeover in Oracle Utilities Network Management System"
            },
            "type": "title"
          },
          {
            "details": {
              "added": [],
              "removed": [
                "CWE-284"
              ]
            },
            "type": "weaknesses"
          }
        ],
        "id": "1158417a-a780-48fc-9026-5dfe57fdb8c0"
      },
      {
        "created": "2026-09-20T08:00:00+00:00",
        "data": [
          {
            "details": {
              "new": "Low‑Privileged Takeover in Oracle Utilities Network Management System",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "f71cd677-6c98-4b72-b97b-cff65ec430c9"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:oracle:utilities_network_management_system:*:*:*:*:*:*:*:*"
      ],
      "providers": [
        "mitre"
      ]
    },
    "created": {
      "data": "2026-09-15T20:05:21.484000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide).  Supported versions that are affected are 2.4.0.1.0-2.4.0.1.33, 2.5.0.1.0-2.5.0.1.19, 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A and  25.12.0.0.0-25.12.0.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Utilities Network Management System executes to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Network Management System. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 7.8,
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.00113
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "no",
            "Exploitation": "none",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://www.oracle.com/security-alerts/cspusep2026.html"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": "Low‑Privileged Takeover in Oracle Utilities Network Management System",
      "provider": "enrichment"
    },
    "updated": {
      "data": "2026-09-20T07:45:16.279253+00:00",
      "provider": "enrichment"
    },
    "vendors": {
      "data": [
        "oracle",
        "oracle$PRODUCT$utilities_network_management_system"
      ],
      "providers": [
        "mitre",
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-269"
      ],
      "providers": [
        "nvd",
        "vulnrichment"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-09-15T20:05:21.484000+00:00",
    "description": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide).  Supported versions that are affected are 2.4.0.1.0-2.4.0.1.33, 2.5.0.1.0-2.5.0.1.19, 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A and  25.12.0.0.0-25.12.0.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Utilities Network Management System executes to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Network Management System. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "no",
          "Exploitation": "none",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": null,
    "updated": "2026-09-17T12:50:06.530000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2026/83xxx/CVE-2026-83342.json",
    "weaknesses": [
      "CWE-269"
    ]
  }
}