CVE-2026-60960
Oracle · SDP Number Portability
A severe vulnerability in Oracle SDP Number Portability allows authenticated, low-privileged local attackers to achieve system takeover and impact additional connected products.
Executive summary
A critical, easily exploitable vulnerability in Oracle SDP Number Portability permits authenticated local attackers to take over the system and potentially affect other integrated infrastructure.
Vulnerability
The vulnerability exists in the Internal Operations component and requires an attacker to have local logon access to the infrastructure. Due to the scope change associated with this flaw, a successful attack can extend beyond the immediate product to compromise broader infrastructure.
Business impact
The CVSS score of 8.8 highlights the severe nature of this vulnerability, particularly due to its potential for scope escalation. If exploited, an attacker could transition from a low-privileged local user to full system control, potentially impacting the availability and integrity of global telecommunications routing data.
Remediation
Immediate Action: Apply the security patches detailed in the July 2026 Oracle Critical Patch Update specifically for the SDP Number Portability component.
Proactive Monitoring: Review system logs for unauthorized privilege escalation attempts and monitor for any unusual cross-process activity that could indicate scope-changing attacks.
Compensating Controls: Implement strict local access controls and ensure that only authorized personnel have login permissions on servers hosting the SDP Number Portability software.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the risk of scope change and full system takeover, this vulnerability must be patched with high urgency. Administrators should prioritize the application of the July 2026 security updates to all affected Oracle SDP Number Portability installations to maintain infrastructure integrity.