# CVE-2026-83343

## Summary

- **CVE ID:** CVE-2026-83343
- **Severity:** HIGH
- **CVSS Score:** 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N)
- **CWE:** N/A
- **Published:** Sep 15, 2026
- **Last Modified:** Sep 15, 2026

## Description

Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide).  Supported versions that are affected are 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A and  25.12.0.0.0-25.12.0.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Utilities Network Management System accessible data as well as  unauthorized update, insert or delete access to some of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).

## Affected Products

- Oracle Corporation — Oracle Utilities Network Management System (2.5.0.2.0)
- Oracle Corporation — Oracle Utilities Network Management System (2.6.0.1.0)
- Oracle Corporation — Oracle Utilities Network Management System (2.6.0.2.0)
- Oracle Corporation — Oracle Utilities Network Management System (25.12.0.0.0)

## References

- [CNA](https://www.oracle.com/security-alerts/cspusep2026.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.35%
- **EPSS Percentile:** 29.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._