Executive brief
A critical vulnerability exists in the Messaging Enabler component of Oracle's Service Delivery Platform, a middleware solution used for managing communications services. An attacker with basic network access can take full control of the platform, potentially leading to the theft of sensitive data or a complete shutdown of the service. Because this component interacts with other systems, a successful attack could also compromise additional connected business applications.
Technical details
A vulnerability in the Messaging Enabler component of Oracle Service Delivery Platform (part of Fusion Middleware) allows for complete system compromise. The flaw is easily exploitable by a low-privileged attacker with network access via the T3 or IIOP protocols. The vulnerability is notable for a 'scope change' (CVSS S:C), meaning a successful exploit can impact resources beyond the Service Delivery Platform itself. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed: Initial advisory publication by Oracle