Junglewise Threat Intelligence

CVE-2026-60386: Oracle Service Delivery Platform remote compromise in Messaging Enabler

CVE-2026-60386 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle Service Delivery Platform. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle's Service Delivery Platform, a component used for managing communication services. An attacker can remotely take full control of the system over the internet without needing any login credentials. This could lead to a total loss of data confidentiality, system integrity, and service availability.

Technical details

This vulnerability affects the Messaging Enabler component of Oracle Fusion Middleware's Service Delivery Platform. It is characterized by a low attack complexity and requires no user interaction or prior authentication. An attacker can exploit this flaw over the network via HTTP to achieve a complete takeover of the affected instance. The vulnerability impacts versions 12.2.1.4.0 and 14.1.2.0.0, resulting in high impacts to confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats