Junglewise Threat Intelligence

CVE-2026-60440: Oracle Service Delivery Platform information disclosure in Messaging Enabler

CVE-2026-60440 · Severity: high · CVSS 7.7 · Published 2026-07-21

Technologies: Oracle Service Delivery Platform. Vendors: Oracle.

Executive brief

A vulnerability exists in the Messaging Enabler component of Oracle's Service Delivery Platform, a system used by telecommunications and service providers to manage service logic and delivery. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive data. This breach could lead to the exposure of critical business information and potentially impact other integrated systems beyond the platform itself.

Technical details

This vulnerability affects the Messaging Enabler component of Oracle Fusion Middleware's Service Delivery Platform (versions 12.2.1.4.0 and 14.1.2.0.0). It is classified as an information disclosure flaw that is easily exploitable via the HTTP protocol. An attacker requires only low-level privileges (PR:L) and network access (AV:N) to execute the exploit. The vulnerability is notable for a 'Scope Change' (S:C), indicating that a successful exploit can impact components or data outside the immediate security scope of the Service Delivery Platform. The primary impact is on confidentiality (C:H), potentially allowing complete access to all accessible data within the platform. Users should refer to the Oracle July 2026 Critical Patch Update for remediation.

Affected products

  • Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60440 by Oracle
  • 2026-07-21: advisory: Included in Oracle July 2026 Critical Patch Update

References

Related threats