Junglewise Threat Intelligence

CVE-2026-82999: Oracle Service Delivery Platform privilege escalation via Messaging Enabler

CVE-2026-82999 · Severity: critical · CVSS 9.9 · Published 2026-09-15

Executive brief

Oracle Service Delivery Platform is a messaging and communication service used within Oracle Fusion Middleware deployments. A flaw in the Messaging Enabler component allows a low-privileged attacker with network access to escalate their privileges and take over the platform, potentially impacting multiple systems due to scope change. This could result in full compromise of the platform including data theft and service disruption.

Technical details

This is an easily exploitable privilege escalation vulnerability in the Messaging Enabler component of Oracle Service Delivery Platform. The vulnerability requires low privileges and network access via HTTP, with no user interaction needed. An authenticated attacker can leverage this flaw to gain administrative control over the Service Delivery Platform. The scope change designation indicates that exploitation may affect other connected Oracle Fusion Middleware products beyond the platform itself. Patches are expected to be available from Oracle as part of their security updates.

Affected products

  • Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: advisory

References

Related threats