Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Messaging Enabler component of Oracle Fusion Middleware Service Delivery Platform has a flaw that allows an unauthenticated attacker with HTTP network access to take full control of the platform, compromising confidentiality, integrity, and availability. The weakness originates from improper access control that enables remote code execution.

Affected Systems

Oracle Service Delivery Platform versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These releases expose an HTTP endpoint that can be reached by anyone on the network, permitting the exploitation described.

Risk and Exploitability

The CVSS base score of 9.8 marks the vulnerability as critical. The EPSS score is below 1%, indicating a very low current exploitation probability, though the issue is not listed in CISA KEV. Attackers can reach the vulnerable endpoint over the network via HTTP without authentication; the exploit is described as easily exploitable and can result in full takeover of the platform.

Generated by OpenCVE AI on August 2, 2026 at 22:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle update that fixes the Messaging Enabler vulnerability on Service Delivery Platform.
  • Limit HTTP access to the platform by restricting connections to trusted IP ranges or requiring a VPN.
  • Block or monitor the exposed Messaging Enabler HTTP endpoint with a firewall or network segmentation to reduce the attack surface.
  • Deploy security monitoring or intrusion detection to detect anomalous HTTP requests targeting the Messaging Enabler.

Generated by OpenCVE AI on August 2, 2026 at 22:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Messaging Enabler Remote Code Execution Vulnerability in Oracle Service Delivery Platform

Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via HTTP on Oracle Service Delivery Platform
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via HTTP on Oracle Service Delivery Platform
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:51:02.029Z

Reserved: 2026-07-08T15:51:40.534Z

Link: CVE-2026-60386

cve-icon Vulnrichment

Updated: 2026-07-24T16:50:44.171Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:45:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function