A critical, network-exploitable flaw in Oracle Fusion Middleware's Service Delivery Platform lets an unauthenticated attacker fully compromise the product over HTTP, earning a CVSS 3.1 base score of 9.8.
What Is It
CVE-2026-60380 is a vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware, specifically in the Messaging Enabler component. The flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the Service Delivery Platform. Successful attacks can result in complete takeover of the platform. Oracle sourced the record ([email protected]), and it was published on July 21, 2026.
Why It Matters
The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That means network attack vector, low attack complexity, no privileges required, and no user interaction; with high impact to confidentiality, integrity, and availability. In practical terms, an attacker on the network can take over the platform without credentials or user assistance, making this an urgent priority for any exposed deployment.
What's Vulnerable
The affected product is Oracle Corporation's Service Delivery Platform (component: Messaging Enabler). The supported versions confirmed as affected are:
- 12.2.1.4.0
- 14.1.2.0.0
Patch Status
The supplied source material links to Oracle's Critical Patch Update advisory for July 2026 (cpujul2026.html) as the reference for this CVE. No CISA KEV entry was supplied for CVE-2026-60380, so active exploitation is not confirmed in the provided data, and no separate required-action remediation directive is present. Administrators running the affected versions should consult Oracle's July 2026 Critical Patch Update for fixes.
Sources
- Oracle Critical Patch Update Advisory; July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60380: https://nvd.nist.gov/vuln/detail/CVE-2026-60380