Executive brief
A critical vulnerability has been identified in Oracle's Service Delivery Platform, a middleware component used for managing communications and messaging services. An attacker can remotely take full control of the system over the network without needing any usernames or passwords. This could lead to a total loss of data confidentiality, unauthorized changes to system settings, and service outages.
Technical details
A vulnerability in the Messaging Enabler component of Oracle Service Delivery Platform allows for complete system takeover. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation grants the attacker full control over the affected Service Delivery Platform instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory