Executive brief
A critical vulnerability exists in Oracle's Service Delivery Platform, a middleware component used for managing communications and messaging services. An unauthorized attacker can remotely take full control of the system over the network without needing any login credentials. This could lead to a total loss of data confidentiality, system integrity, and service availability.
Technical details
A vulnerability in the Messaging Enabler component of Oracle Fusion Middleware's Service Delivery Platform allows for complete system takeover. The flaw is easily exploitable by an unauthenticated attacker with network access via the T3 or IIOP protocols. Successful exploitation grants the attacker full control over the Service Delivery Platform, impacting confidentiality, integrity, and availability (CVSS 9.8). Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date