Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Service Delivery Platform accessible data as well as unauthorized access to critical data or complete access to all Service Delivery Platform accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Service Delivery Platform permits a low‑privileged attacker with network access via Oracle Net to create, delete, or modify critical data, granting unauthorized and complete access to all data handled by the platform. The flaw, described as easily exploitable, can cause significant loss of confidentiality and integrity. The CVSS 3.1 base score of 9.6 reflects the severe impact on confidentiality and integrity, while availability is not affected.

Affected Systems

The affected products are Oracle Corporation Service Delivery Platform versions 12.2.1.4.0 and 14.1.2.0.0 running on Oracle Fusion Middleware. No other versions are listed as vulnerable.

Risk and Exploitability

The risk is high due to the high CVSS score and the possibility of a remote attack vector (network access). The exploitability is likely straightforward for an attacker possessing low privileges on the network, as the issue can be triggered by crafted messages sent over Oracle Net. This vulnerability also poses a scope change, potentially impacting additional Oracle products. While the EPSS score is < 1% and the vulnerability is not listed in CISA KEV, the severity and potential for wide‑reaching effects warrant immediate attention.

Generated by OpenCVE AI on August 21, 2026 at 14:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest Oracle patch for Service Delivery Platform 12.2.1.4.0 or 14.1.2.0.0 that addresses the authorization flaw.
  • If a patch is not yet released, upgrade to a newer supported major release of the platform.
  • Restrict Oracle Net network access to trusted hosts using firewalls or ACLs to limit the potential attack surface.
  • Configure least‑privilege access controls within the platform and monitor for unauthorized creation, deletion, or modification events.
  • Review and adjust application logs to detect and alert on anomalous data access patterns.

Generated by OpenCVE AI on August 21, 2026 at 14:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle fusion Middleware
CPEs cpe:2.3:a:oracle:fusion_middleware:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:fusion_middleware:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:-:*:*:*:*:*:*:*
Vendors & Products Oracle fusion Middleware

Fri, 21 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Title Oracle Service Delivery Platform Low-Privilege Remote Data Access Exploit

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Service Delivery Platform accessible data as well as unauthorized access to critical data or complete access to all Service Delivery Platform accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Fusion Middleware Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T18:13:23.702Z

Reserved: 2026-07-08T15:51:55.597Z

Link: CVE-2026-60861

cve-icon Vulnrichment

Updated: 2026-08-20T18:12:36.275Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:45.630

Modified: 2026-08-21T14:59:46.250

Link: CVE-2026-60861

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T14:15:07Z

Weaknesses