ZeroHour

CVE-2026-83000

niche

Unauthenticated HTTP Takeover Flaw in Oracle Service Delivery Platform Messaging Enabler

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

Oracle Fusion Middleware's Service Delivery Platform contains a critical vulnerability in its Messaging Enabler component, affecting versions 12.2.1.4.0 and 14.1.2.0.0. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. A successful attack allows complete takeover of the Service Delivery Platform, with high impact on the confidentiality, integrity, and availability of the system (CVSS 3.1 base score 9.8). Organizations running telecom-grade Oracle SDP deployments on the affected versions are exposed wherever the Messaging Enabler HTTP interfaces are reachable. No public proof-of-concept exists and the CVE is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation status is currently none known.

What to do: Apply the Oracle Critical Patch Update that remediates this CVE to all Service Delivery Platform instances running 12.2.1.4.0 or 14.1.2.0.0. Until patched, restrict network access to the Messaging Enabler HTTP endpoints so only trusted internal systems can reach them. Review HTTP access logs on SDP servers for unauthenticated or anomalous requests to Messaging Enabler endpoints.

Affected
Oracle Fusion Middleware - Service Delivery Platform (Messaging Enabler component)
Estimated exposure
nichelikely hundreds to low thousands of installations worldwide (carrier/enterprise deployments) — Oracle Service Delivery Platform is carrier-grade telecom middleware deployed by a limited set of communications service providers rather than mass-distributed software, and no public install counts or internet-exposure scan data are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.