Junglewise Threat Intelligence

CVE-2026-60389: Oracle Service Delivery Platform remote compromise in Messaging Enabler

CVE-2026-60389 · Severity: critical · CVSS 10 · Published 2026-07-21

Technologies: Oracle Service Delivery Platform. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle's Service Delivery Platform, a middleware component used for managing communication services. An unauthenticated attacker can remotely take full control of the system over the network. This could lead to a total loss of data confidentiality and service availability, potentially impacting other connected business systems.

Technical details

This vulnerability affects the Messaging Enabler component of Oracle Service Delivery Platform (versions 12.2.1.4.0 and 14.1.2.0.0). It is categorized as easily exploitable, requiring no authentication or user interaction (CVSS 10.0). An attacker can exploit this flaw over the network via HTTP to achieve a complete compromise of the host. Notably, the vulnerability includes a 'scope change' (S:C), meaning a successful attack can extend beyond the Service Delivery Platform to impact other components or products within the environment. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60389
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats