Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in the Messaging Enabler component of Oracle's Service Delivery Platform, allowing an attacker who can reach the platform over the T3 or IIOP protocols, even with only low privileges, to acquire unauthorized access that can lead to complete takeover of the platform. The flaw is an instance of improper access control (CWE‑284) and would give the attacker control over confidential, integral, and available resources, effectively enabling remote code execution and full compromise of the affected service.

Affected Systems

Affected installations include Oracle Corporation's Service Delivery Platform in the Fusion Middleware suite. The issue impacts versions 12.2.1.4.0 and 14.1.2.0.0. No other products are directly referenced, but the description notes that successful exploitation may extend to other Oracle services through scope amplification.

Risk and Exploitability

The CVSS base score is 9.9, indicating catastrophic impact with confidentiality, integrity, and availability fully compromised. The EPSS score is below 1%, suggesting low current exploitation probability, and the vulnerability is not recorded in CISA's KEV catalog. However, because the attack requires network access to the T3 or IIOP ports and only low privileges, an attacker who can reach the affected host could exploit the flaw with high success probability in a suitable environment. The described scope change means that compromise of the Service Delivery Platform could extend to other Oracle services that run on the same host.

Generated by OpenCVE AI on September 17, 2026 at 04:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy Oracle’s latest security patch specific to Service Delivery Platform versions 12.2.1.4.0 and 14.1.2.0.0, as detailed in Oracle’s security alert for CVE‑2026‑82998.
  • Restrict inbound traffic to the T3 and IIOP ports to trusted hosts or VPNs, and enforce strict firewall rules around the Service Delivery Platform.
  • Disable the Messaging Enabler feature or isolate the Service Delivery Platform instance if patch deployment is delayed.

Generated by OpenCVE AI on September 17, 2026 at 04:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Access in Oracle Service Delivery Platform Messaging Enabler Allows Platform Takeover

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:28:30.825Z

Reserved: 2026-08-31T15:40:57.329Z

Link: CVE-2026-82998

cve-icon Vulnrichment

Updated: 2026-09-16T14:54:36.583Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:06.343

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-82998

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:45:17Z

Weaknesses