Junglewise Threat Intelligence

CVE-2026-83151: Oracle Service Delivery Platform remote code execution in Messaging Enabler

CVE-2026-83151 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Executive brief

Oracle Service Delivery Platform is a middleware component used to deliver business-critical messaging and integration services. An unauthenticated attacker on the network can exploit this vulnerability via SOAP to gain complete control of the platform, leading to potential data theft, service disruption, and system compromise.

Technical details

This vulnerability in the Messaging Enabler component of Oracle Service Delivery Platform allows unauthenticated remote code execution via SOAP protocol. The attack requires only network access with no authentication, user interaction, or complex configuration needed (CVSS vector indicates AV:N/AC:L/PR:N/UI:N). Successful exploitation results in complete takeover of the Service Delivery Platform, compromising confidentiality, integrity, and availability. Affected versions are 12.2.1.4.0 and 14.1.2.0.0.

Affected products

  • Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats