Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Messaging Enabler component of Oracle Service Delivery Platform allows an unauthenticated attacker with network access via HTTP to compromise the entire platform. The flaw enables full takeover, leading to loss of confidentiality, integrity, and availability. This represents a high‑severity remote code execution weakness, as reflected in the CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected Systems

Oracle Corporation’s Service Delivery Platform (Fusion Middleware) is impacted. Versions 12.2.1.4.0 and 14.1.2.0.0 are listed as affected. No other vendors or versions are mentioned in the advisories provided.

Risk and Exploitability

The CVSS score of 9.8 indicates critical risk, while the EPSS score of less than 1% suggests that, at present, the likelihood of exploitation is very low. Nonetheless, the vulnerability is not listed in the CISA KEV catalog, meaning it has not yet been confirmed in widespread exploitation, but the potential impact remains high. The attack vector is inferred to be remote over HTTP, with no authentication required, so any network‑connected host that can reach the Messaging Enabler endpoint could be targeted.

Generated by OpenCVE AI on August 2, 2026 at 22:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s security portal for a patch or update for Service Delivery Platform 12.2.1.4.0 and 14.1.2.0.0 and apply it as soon as it becomes available.
  • If a patch is not yet released, block external HTTP traffic to the Messaging Enabler component using network firewalls or ACLs to limit exposure to trusted hosts only.
  • Disable or remove the Messaging Enabler service from the platform until a fix is deployed, and routinely validate that the service remains inactive.
  • Consider applying the principles associated with Improper Access Control and Remote Code Execution by verifying that any future updates contain proper authentication and input validation.

Generated by OpenCVE AI on August 2, 2026 at 22:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via HTTP in Oracle Service Delivery Platform

Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via HTTP in Oracle Service Delivery Platform Messaging Enabler
Weaknesses CWE-284
CWE-94

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via HTTP in Oracle Service Delivery Platform Messaging Enabler
Weaknesses CWE-284
CWE-94

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:55:08.181Z

Reserved: 2026-07-08T15:51:40.533Z

Link: CVE-2026-60378

cve-icon Vulnrichment

Updated: 2026-07-24T16:53:54.383Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:45:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function