A critical, unauthenticated vulnerability in Oracle's Service Delivery Platform lets remote attackers fully compromise the product over the network with a CVSS score of 10.0.
What Is It
CVE-2026-60379 is a vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware, specifically in the Messaging Enabler component. Oracle rates it a maximum CVSS 3.1 Base Score of 10.0 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. The flaw is described as easily exploitable and allows an unauthenticated attacker with network access via SOAP to compromise the platform. Successful attacks can result in complete takeover of the Service Delivery Platform.
Why It Matters
This is a worst-case scoring profile: network attack vector, low complexity, no privileges, and no user interaction required. The vulnerability carries a scope change (S:C), meaning that although the flaw resides in Service Delivery Platform, attacks may significantly impact additional products beyond it. Impact is high across confidentiality, integrity, and availability; a full takeover. The combination of unauthenticated reachability over SOAP and a perfect 10.0 rating makes this a high-priority patching target.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Service Delivery Platform (Oracle Fusion Middleware)
- Component: Messaging Enabler
- Affected versions: 12.2.1.4.0 and 14.1.2.0.0
Patch Status
The vulnerability was published in Oracle's July 2026 Critical Patch Update. Administrators should consult the Oracle Critical Patch Update Advisory for July 2026 and apply the corresponding fixes for the affected versions. No CISA KEV entry confirming active exploitation was supplied with this record.
Sources
- Oracle Critical Patch Update Advisory – July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- NVD – CVE-2026-60379: https://nvd.nist.gov/vuln/detail/CVE-2026-60379