ZeroHour

CVE-2026-82999

niche

Authenticated Takeover Flaw in Oracle Service Delivery Platform Messaging Enabler (CVSS 9.9)

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

Oracle Service Delivery Platform, a component of Oracle Fusion Middleware (specifically its Messaging Enabler component), contains an easily exploitable vulnerability in versions 12.2.1.4.0 and 14.1.2.0.0. A remote attacker with only low-privileged credentials and HTTP network access to the platform can exploit the flaw, which successful exploitation results in a complete takeover of the Service Delivery Platform. Because the vulnerability has a scope change (CVSS S:C), successful attacks may also significantly impact additional products beyond Service Delivery Platform itself, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 9.9). Affected organizations are typically communications and digital service providers running Oracle SDP on the listed Fusion Middleware versions. No public proof of concept is known and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation status is currently none known.

What to do: Apply the latest Oracle Critical Patch Update to Service Delivery Platform installations running 12.2.1.4.0 or 14.1.2.0.0 as soon as patches are available. Restrict HTTP access to SDP and Messaging Enabler interfaces to trusted administrative networks, and enforce least privilege and strong credential controls for all SDP accounts since valid low-privileged access is required. Given the scope-change impact on additional products, review logs for anomalous activity by low-privileged accounts and assess adjacent systems for compromise.

Affected
Oracle Fusion Middleware - Service Delivery Platform (Messaging Enabler)12.2.1.4.0, 14.1.2.0.0
Estimated exposure
nichelikely hundreds to low thousands of deployments worldwide at telecom/service providers (exact count unknown) — Oracle Service Delivery Platform is an enterprise-grade product deployed primarily by communications service providers rather than a mass-market product, and no public install counts or internet-exposed scan data are available, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.