Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Messaging Enabler component of Oracle Service Delivery Platform, identified as an authentication weakness (CWE-306), allows an unauthenticated attacker with network access to the T3 or IIOP protocols to compromise the platform. Successful exploitation can result in a full takeover, giving the attacker control over confidentiality, integrity, and availability of the affected system. The CVSS score of 9.8 reflects the severe impact across all three security dimensions.

Affected Systems

Oracle Corporation’s Service Delivery Platform is impacted, specifically the Fusion Middleware versions 12.2.1.4.0 and 14.1.2.0.0. These releases are listed as affected by the CVE advisory.

Risk and Exploitability

With a CVSS score of 9.8, this vulnerability is considered critical. The EPSS score of less than 1% indicates a low probability that exploitation is occurring in the wild, and the vulnerability is not yet included in CISA’s KEV catalog. The attack requires only network connectivity to the vulnerable ports and no credentials, so any host exposed to the T3 or IIOP traffic presents a potential vector for immediate compromise.

Generated by OpenCVE AI on August 4, 2026 at 03:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply the Oracle Service Delivery Platform patch released in the CPU July 2026 advisory
  • Restrict inbound T3 and IIOP traffic to trusted networks only by configuring firewalls or network segmentation
  • Monitor logs for unusual activity or unauthorized access attempts and investigate immediately

Generated by OpenCVE AI on August 4, 2026 at 03:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Exploitation of Oracle Service Delivery Platform Messaging Enabler

Tue, 28 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Attack on Oracle Service Delivery Platform Leads to Full Compromise
Weaknesses CWE-284

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Attack on Oracle Service Delivery Platform Leads to Full Compromise
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:17:45.834Z

Reserved: 2026-07-08T15:51:40.537Z

Link: CVE-2026-60441

cve-icon Vulnrichment

Updated: 2026-07-24T14:17:35.501Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:00:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function