ZeroHour

CVE-2026-82998

niche

Privilege Escalation to Full Takeover in Oracle Service Delivery Platform via T3/IIOP

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-82998 is a critical (CVSS 9.9) vulnerability in the Messaging Enabler component of Oracle Service Delivery Platform, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploited by a low-privileged (authenticated) attacker with network access via the T3 or IIOP protocols, which are commonly used for Java remote method invocation in WebLogic-based deployments. A successful attack results in complete takeover of the Service Delivery Platform, and because the vulnerability carries a scope change (S:C), compromises can significantly impact additional products beyond the initial target, with high impacts to confidentiality, integrity, and availability. The product is primarily deployed by telecommunications carriers and large service providers running Oracle Communications software. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild is currently known.

What to do: Apply the Oracle Critical Patch Update that remediated CVE-2026-82998 to all Service Delivery Platform instances on 12.2.1.4.0 and 14.1.2.0.0. Restrict or disable T3 and IIOP network access at the perimeter so only trusted internal hosts can reach those ports, and verify no SDP T3/IIOP listeners are internet-exposed via external scanning. Review authentication logs for unexpected low-privilege account activity and rotate credentials on affected systems as a precaution.

Affected
Oracle Service Delivery Platform (Oracle Fusion Middleware, component: Messaging Enabler)
Estimated exposure
nichelikely hundreds to low thousands of deployments worldwide (carrier/service-provider installations); unknown number with T3/IIOP ports internet-exposed — Oracle Service Delivery Platform is carrier-grade communications software licensed to a limited set of telecom operators rather than a mass-market product, so deployment counts are inherently small, though individual deployments may serve…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.