CVE-2026-82999
nicheAuthenticated Takeover Flaw in Oracle Service Delivery Platform Messaging Enabler (CVSS 9.9)
Oracle Service Delivery Platform, a component of Oracle Fusion Middleware (specifically its Messaging Enabler component), contains an easily exploitable vulnerability in versions 12.2.1.4.0 and 14.1.2.0.0. A remote attacker with only low-privileged credentials and HTTP network access to the platform can exploit the flaw, which successful exploitation results in a complete takeover of the Service Delivery Platform. Because the vulnerability has a scope change (CVSS S:C), successful attacks may also significantly impact additional products beyond Service Delivery Platform itself, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 9.9). Affected organizations are typically communications and digital service providers running Oracle SDP on the listed Fusion Middleware versions. No public proof of concept is known and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation status is currently none known.
What to do: Apply the latest Oracle Critical Patch Update to Service Delivery Platform installations running 12.2.1.4.0 or 14.1.2.0.0 as soon as patches are available. Restrict HTTP access to SDP and Messaging Enabler interfaces to trusted administrative networks, and enforce least privilege and strong credential controls for all SDP accounts since valid low-privileged access is required. Given the scope-change impact on additional products, review logs for anomalous activity by low-privileged accounts and assess adjacent systems for compromise.
| Oracle Fusion Middleware - Service Delivery Platform (Messaging Enabler) | 12.2.1.4.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.