Improper input validation in Oracle Communications Session Report Manager - CVE-2026-23903
Published: April 22, 2026
Oracle Communications Session Report Manager
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The vulnerability exists due to improper input validation within the Third Party (Apache Shiro) component in Oracle Communications Session Report Manager. A remote non-authenticated attacker can exploit this vulnerability to gain access to sensitive information.