Junglewise Threat Intelligence

CVE-2026-82998: Oracle Fusion Middleware Service Delivery Platform privilege escalation in Messaging Enabler

CVE-2026-82998 · Severity: critical · CVSS 9.9 · Published 2026-09-15

Executive brief

Oracle Fusion Middleware's Service Delivery Platform is a middleware component that handles messaging and service delivery operations in enterprise systems. A privilege escalation vulnerability in the Messaging Enabler component allows an attacker with low-level network access to take over the entire platform and potentially impact other connected systems, resulting in complete compromise of confidentiality, integrity, and availability.

Technical details

The vulnerability is an easily exploitable privilege escalation flaw in the Messaging Enabler component of Oracle Fusion Middleware's Service Delivery Platform. It requires low privileged access and network connectivity via T3 or IIOP protocols. A successful exploit allows an attacker to achieve complete control over the affected platform, with scope change indicating that the compromise may extend to other products in the Oracle Fusion Middleware environment. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0.

Affected products

  • Oracle Fusion Middleware Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats