Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an authentication bypass (CWE-306). An unauthenticated attacker with network access via HTTP can exploit the Messaging Enabler component in the Service Delivery Platform to gain complete control over the platform. This leads to exposure of all confidential data, compromise of user sessions, and disruption of service availability. The CVE explicitly states that successful attacks can result in takeover of the Service Delivery Platform.

Affected Systems

Oracle Service Delivery Platform versions 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware, are affected. The Messaging Enabler component in these versions can be exploited.

Risk and Exploitability

The CVSS 3.1 base score of 9.8 indicates critical impact. EPSS score is less than 1%, suggesting limited current exploitation probability. The vulnerability is not listed in CISA KEV. Attack vector is network-based over HTTP, requiring no prior authentication. Even though exploitation may be uncommon, the potential for complete platform compromise warrants urgent attention.

Generated by OpenCVE AI on August 2, 2026 at 22:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for the Service Delivery Platform covering versions 12.2.1.4.0 and 14.1.2.0.0.
  • Restrict HTTP access to the platform with firewall rules or access control lists to allow only trusted IP ranges.
  • Enforce authentication and upgrade communications to HTTPS, disabling any unsecured endpoints.

Generated by OpenCVE AI on August 2, 2026 at 22:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Allowing Full Service Delivery Platform Compromise

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Allowing Full Service Delivery Platform Compromise

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T13:58:19.808Z

Reserved: 2026-07-08T15:51:40.533Z

Link: CVE-2026-60380

cve-icon Vulnrichment

Updated: 2026-07-24T13:58:11.906Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:45:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function