Junglewise Threat Intelligence

CVE-2026-60382: Oracle Service Delivery Platform denial of service in Messaging Enabler

CVE-2026-60382 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Oracle Service Delivery Platform. Vendors: Oracle.

Executive brief

A vulnerability exists in the Messaging Enabler component of Oracle's Service Delivery Platform, which is used to manage communications within enterprise middleware environments. An unauthenticated attacker can remotely exploit this flaw over the network to cause the system to hang or crash repeatedly. This results in a complete denial of service, preventing legitimate users and business processes from accessing the platform's messaging capabilities.

Technical details

A vulnerability in the Messaging Enabler component of Oracle Service Delivery Platform (part of Fusion Middleware) allows for a denial of service (DoS). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation enables the attacker to cause a hang or a frequently repeatable crash of the Service Delivery Platform, impacting system availability. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats