Executive brief
A critical vulnerability exists in the Oracle Service Delivery Platform, a component of Fusion Middleware used for managing communication services. An attacker can remotely take full control of the system without needing a username or password. This could lead to a total loss of data confidentiality, system integrity, and service availability, potentially disrupting business operations and exposing sensitive communications.
Technical details
A vulnerability in the Messaging Enabler component of Oracle Fusion Middleware's Service Delivery Platform allows for complete system takeover. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. It carries a CVSS 3.1 base score of 9.8, indicating high impact on confidentiality, integrity, and availability. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. While specific CWE details are not provided in the advisory, the 'takeover' description and CVSS vector suggest a critical authentication bypass or remote code execution flaw. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation.
Affected products
- Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory