A critical, easily exploitable flaw in Oracle's Service Delivery Platform lets an unauthenticated remote attacker fully compromise the product over HTTP, earning a CVSS 3.1 score of 9.8.
What Is It
CVE-2026-60378 is a vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware, specifically in the Messaging Enabler component. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the Service Delivery Platform. A successful attack can result in complete takeover of the platform.
Why It Matters
The vulnerability carries a CVSS 3.1 Base Score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That combination, network attack vector, low complexity, no privileges required, and no user interaction, means an attacker needs only network reachability to exploit it. The impact spans High Confidentiality, High Integrity, and High Availability, reflecting the potential for full product takeover. Oracle notes the vulnerability is "easily exploitable," raising the practical risk to exposed instances.
What's Vulnerable
The affected product is Oracle Service Delivery Platform (Oracle Corporation), component Messaging Enabler. Supported versions confirmed affected are:
- 12.2.1.4.0
- 14.1.2.0.0
Patch Status
This CVE was published as part of Oracle's Critical Patch Update for July 2026. Organizations running the affected versions should apply the fixes referenced in the Oracle Critical Patch Update advisory. No entry confirming active exploitation was present in the supplied CISA KEV data, so exploitation-in-the-wild is not confirmed here; given the 9.8 severity and unauthenticated network attack surface, prompt patching is strongly advised.
Sources
- Oracle Critical Patch Update Advisory (July 2026), https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60378, https://nvd.nist.gov/vuln/detail/CVE-2026-60378