ZeroHour

CVE-2026-82997

niche

Low-Privilege Takeover in Oracle Service Delivery Platform via T3/IIOP

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-82997 is a critical (CVSS 9.9) vulnerability in the Messaging Enabler component of Oracle's Service Delivery Platform, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. A remote attacker with only low-privileged (authenticated) access to the T3 or IIOP network interfaces can exploit the flaw easily and completely take over the Service Delivery Platform, and because the vulnerability has a scope change, successful attacks can also significantly impact additional products, with high impact to confidentiality, integrity, and availability. The affected deployments are Oracle Communications Service Delivery Platform installations at communications service providers, primarily telecom operators running carrier-grade messaging infrastructure. No public proof-of-concept code is known and the flaw is not on CISA's Known Exploited Vulnerabilities catalog, so exploitation in the wild is not currently evidenced.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-82997 to all Service Delivery Platform 12.2.1.4.0 and 14.1.2.0.0 installations. Until patched, block or tightly firewall the T3 and IIOP listeners (commonly WebLogic ports such as 7001/7002 and the IIOP port) at the network perimeter so only trusted administrative subnets can reach them, and consider disabling IIOP entirely if unused. Review low-privileged account activity and WebLogic/T3 session logs for anomalous connections, and verify with external scanning that no SDP protocol ports are exposed to the internet.

Affected
Oracle Fusion Middleware / Service Delivery Platform (component: Messaging Enabler)12.2.1.4.0, 14.1.2.0.0
Estimated exposure
nichelikely hundreds to low thousands of telecom-operator deployments worldwide — Service Delivery Platform is a carrier-grade Oracle Communications product licensed to a limited population of communications service providers rather than mass-market software, so the install base is inherently small and vendor-published…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.