Executive brief
A critical vulnerability has been identified in Oracle Fusion Middleware's Service Delivery Platform, specifically within the Messaging Enabler component. This platform is used to manage and deliver communication services across enterprise networks. An attacker could exploit this flaw to gain full control over the system, potentially leading to the theft of sensitive data, service disruptions, and unauthorized access to connected corporate systems.
Technical details
A vulnerability in the Messaging Enabler component of Oracle Fusion Middleware Service Delivery Platform allows for remote code execution or full system compromise. The flaw is easily exploitable by an unauthenticated attacker with network access via the SOAP protocol. The vulnerability is characterized by a 'scope change' (S:C), meaning a successful exploit can impact not only the Service Delivery Platform itself but also other integrated products and components within the environment. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory