ZeroHour

CVE-2026-83151

niche

Unauthenticated SOAP Flaw Allows Full Takeover of Oracle Service Delivery Platform

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

Oracle Service Delivery Platform (a Fusion Middleware product, specifically the Messaging Enabler component) contains an easily exploitable vulnerability that lets an unauthenticated remote attacker compromise the platform through its SOAP interface over the network. Successful exploitation can result in a complete takeover of the Service Delivery Platform, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 9.8, vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Versions 12.2.1.4.0 and 14.1.2.0.0 are the supported releases confirmed as affected. The product is primarily deployed by communications service providers, so exposure is limited to telecom operator environments rather than the general internet. No public proof-of-concept exists and the flaw is not on CISA's Known Exploited Vulnerabilities catalog, so exploitation is currently none known.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83151 to Service Delivery Platform 12.2.1.4.0 and 14.1.2.0.0 as soon as possible. Restrict network access to the Messaging Enabler SOAP endpoints so only trusted internal systems (e.g., charging, provisioning, and mediation platforms) can reach them, and block unauthenticated SOAP traffic at perimeter firewalls. Review logs for unexpected SOAP requests or administrative activity against these endpoints to rule out prior exploitation.

Affected
Oracle Service Delivery Platform (Fusion Middleware, Messaging Enabler component)12.2.1.4.0, 14.1.2.0.0
Estimated exposure
nichelikely hundreds of installations worldwide (telecom carrier deployments) — Oracle Service Delivery Platform is carrier-grade communications software licensed to telecom operators rather than mass-market software, so the install base is a small population of service-provider data centers, though each instance may…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.