Executive brief
A critical vulnerability exists in Oracle's Service Delivery Platform, a middleware component used for managing communication services. An unauthenticated attacker can remotely take full control of the system over the network. This could lead to a total loss of data confidentiality and service availability, potentially impacting other connected business systems.
Technical details
This vulnerability affects the Messaging Enabler component of Oracle Service Delivery Platform (versions 12.2.1.4.0 and 14.1.2.0.0). It is categorized as easily exploitable, requiring no authentication or user interaction (CVSS 10.0). An attacker can exploit this flaw over the network via HTTP to achieve a complete compromise of the host. Notably, the vulnerability includes a 'scope change' (S:C), meaning a successful attack can extend beyond the Service Delivery Platform to impact other components or products within the environment. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-60389
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released