Executive brief
A critical vulnerability exists in the Messaging Enabler component of Oracle Service Delivery Platform, a middleware solution used for managing communications services. An unauthenticated attacker can remotely exploit this flaw over a network to gain full control of the platform. This could lead to a complete compromise of the system, including unauthorized access to sensitive data and disruption of critical business operations.
Technical details
A critical vulnerability in the Messaging Enabler component of Oracle Fusion Middleware's Service Delivery Platform allows for remote code execution or full system takeover. The flaw is easily exploitable by an unauthenticated attacker with network access via the T3 or IIOP protocols. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. Successful exploitation results in a complete loss of confidentiality, integrity, and availability (CVSS 9.8). Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Initial publication of CVE-2026-60442 by Oracle and NVD.