Executive brief
Oracle Service Delivery Platform, a component of Fusion Middleware used for managing communication services, contains a critical security flaw in its Messaging Enabler component. An unauthorized person can remotely take full control of the platform over the network without needing any login credentials. This could lead to a total loss of data confidentiality, system integrity, and service availability, potentially disrupting business operations and exposing sensitive communications.
Technical details
A critical vulnerability exists in the Messaging Enabler component of Oracle Service Delivery Platform (part of Oracle Fusion Middleware). The flaw is easily exploitable by an unauthenticated attacker with network access via the T3 or IIOP protocols. Successful exploitation allows for a complete compromise and takeover of the Service Delivery Platform, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Initial publication of CVE-2026-60375 by Oracle and NVD.