Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Messaging Enabler component of Oracle Service Delivery Platform’s Fusion Middleware. It is an improper authorization flaw that allows an unauthenticated attacker with access to the platform’s T3 or IIOP interfaces to bypass authentication controls and gain full control of the platform. Successful exploitation results in complete compromise, giving the attacker the ability to execute arbitrary code, access sensitive data, and disrupt services.

Affected Systems

Oracle Service Delivery Platform, versions 12.2.1.4.0 and 14.1.2.0.0, is affected. All instances that deploy the Messaging Enabler component within these releases are vulnerable.

Risk and Exploitability

The CVSS v3.1 base score of 9.8 signals a critical threat. The EPSS score of less than 1% indicates a low probability of exploitation currently, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is unauthenticated and can be reached over network protocols (T3 or IIOP), an attacker who can reach those ports on a hostile network may remotely take full control of the Service Delivery Platform, jeopardizing confidentiality, integrity, and availability.

Generated by OpenCVE AI on August 2, 2026 at 22:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 patch for Service Delivery Platform to fix the Messaging Enabler vulnerability.
  • Restrict network traffic to the T3 and IIOP ports used by the platform to trusted hosts or a secure subnet, and enforce firewall rules to block unsolicited traffic.
  • If the Messaging Enabler is not required for your deployment, disable or uninstall the component to eliminate the attack surface.

Generated by OpenCVE AI on August 2, 2026 at 22:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability via Messaging Enabler in Oracle Service Delivery Platform

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability via Messaging Enabler in Oracle Service Delivery Platform

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:18:25.052Z

Reserved: 2026-07-08T15:51:40.537Z

Link: CVE-2026-60442

cve-icon Vulnrichment

Updated: 2026-07-24T14:18:20.389Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:30:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function