Junglewise Threat Intelligence

CVE-2026-83000: Oracle Fusion Middleware Service Delivery Platform remote code execution via Messaging Enabler

CVE-2026-83000 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Executive brief

Oracle Fusion Middleware's Service Delivery Platform is a mission-critical messaging and service delivery component used by enterprises to manage communications and transactions. An unauthenticated remote attacker can exploit a network-accessible vulnerability in the Messaging Enabler component to gain complete control of the platform, compromising confidentiality, integrity, and availability of customer data and operations without requiring credentials or user interaction.

Technical details

This is a critical remote code execution vulnerability in Oracle Fusion Middleware's Service Delivery Platform, specifically in the Messaging Enabler component. The vulnerability is easily exploitable via HTTP and requires no authentication, making it accessible to any network-connected attacker. The attack requires only network access and no user interaction; successful exploitation results in complete takeover of the platform with impacts across confidentiality, integrity, and availability. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. Patch availability has not been confirmed from the available advisory sources.

Affected products

  • Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed: Published via NVD and Oracle security alert
  • 2026-09-15: other: No evidence of exploitation in wild as of advisory publication date

References

Related threats