A vulnerability was found in Oracle Communications Service Catalog and Design up to 8.3.0.2.0 and classified as critical. Impacted is an unknown function of the component Solution Designer. Such manipulation leads to privilege escalation.

This vulnerability is referenced as CVE-2026-61127. It is possible to launch the attack remotely. No exploit is available.