Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Messaging Enabler component of Oracle Service Delivery Platform allows an unauthenticated attacker to gain full control of the platform using network access via the T3 and IIOP protocols. The vulnerability leads to an unrestricted compromise of confidentiality, integrity, and availability, effectively allowing attackers to take ownership of the Service Delivery Platform.

Affected Systems

The issue affects Oracle Corporation’s Service Delivery Platform product versions 12.2.1.4.0 and 14.1.2.0.0 within the Oracle Fusion Middleware stack.

Risk and Exploitability

The CVSS 3.1 base score of 9.8 underscores the severity of this remote vulnerability. The EPSS score of less than 1% indicates that exploitation is currently rare, and the vulnerability is not yet listed in the CISA KEV catalog. However, the lack of authentication and the high impact suggest that once discovered a malicious actor could exploit this weakness to execute arbitrary code or otherwise take over the system.

Generated by OpenCVE AI on August 2, 2026 at 22:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire and install the latest Oracle Service Delivery Platform patch that addresses the Messaging Enabler flaw.
  • Restrict inbound T3 and IIOP traffic to trusted IP ranges using firewall or network segmentation to reduce exposure to unauthenticated attackers.
  • Configure strict authentication and authorization controls for the Messaging Enabler service to comply with CWE-287, CWE-29, and CWE-306 best practices.

Generated by OpenCVE AI on August 2, 2026 at 22:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via Messaging Enabler in Oracle Service Delivery Platform
Weaknesses CWE-287
CWE-29

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via Messaging Enabler in Oracle Service Delivery Platform
Weaknesses CWE-287
CWE-29

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:02:41.624Z

Reserved: 2026-07-08T15:51:40.533Z

Link: CVE-2026-60375

cve-icon Vulnrichment

Updated: 2026-07-24T17:00:48.818Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:45:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function