Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Messaging Enabler component of Oracle Service Delivery Platform. An unauthenticated attacker can send a specially crafted SOAP request over the network to bypass authentication and gain full control of the platform, leading to compromise of confidentiality, integrity, and availability. The weakness is classified as authentication bypass (CWE-287) and missing authentication or authorization (CWE-306).

Affected Systems

Affected products are Oracle Service Delivery Platform (Fusion Middleware) versions 12.2.1.4.0 and 14.1.2.0.0.

Risk and Exploitability

The CVSS v3.1 base score of 9.8 indicates high impact. The EPSS score of less than 1% suggests the likelihood of exploitation at the moment is very low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network-based, specifically via SOAP over HTTP/HTTPS, and requires no prior authentication. If exploited, an attacker can achieve full takeover of the Service Delivery Platform.

Generated by OpenCVE AI on September 18, 2026 at 21:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check the Oracle security alert at https://www.oracle.com/security-alerts/cspusep2026 update and apply it to the affected platform.
  • If a patch is not yet available, restrict network access to the SOAP services by firewalling or configuring transport layer security to limit exposure.
  • If the Messaging Enabler feature is not required, disable or remove it from the platform to eliminate the attack surface.

Generated by OpenCVE AI on September 18, 2026 at 21:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated SOAP Request Bypasses Authentication to Control Oracle Service Delivery Platform

Thu, 17 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated SOAP Request Bypasses Authentication to Control Oracle Service Delivery Platform

Thu, 17 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-306

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T22:54:36.097Z

Reserved: 2026-08-31T15:40:57.343Z

Link: CVE-2026-83151

cve-icon Vulnrichment

Updated: 2026-09-15T22:45:10.258Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:25.857

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83151

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:15:14Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function