Junglewise Threat Intelligence

CVE-2026-60388: Oracle Service Delivery Platform remote compromise in Messaging Enabler

CVE-2026-60388 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle Service Delivery Platform. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle's Service Delivery Platform, a middleware component used for managing communications and messaging services. An unauthenticated attacker can remotely take full control of the platform over the network. This could lead to a total loss of data confidentiality, system integrity, and service availability, potentially disrupting business operations and exposing sensitive communications.

Technical details

This vulnerability affects the Messaging Enabler component of Oracle Fusion Middleware's Service Delivery Platform. It is easily exploitable by an unauthenticated attacker with network access via the T3 or IIOP protocols. The flaw allows for a complete takeover of the Service Delivery Platform, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats