Oracle has disclosed a critical, easily exploitable flaw in the Service Delivery Platform product of Oracle Fusion Middleware that can lead to full system takeover.
What Is It
CVE-2026-60381 is a critical vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware, specifically the Messaging Enabler component. It carries a CVSS 3.1 base score of 9.9 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The flaw is remotely reachable over the network via the T3 and IIOP protocols and requires only low privileges and no user interaction. Because the scope is changed, a successful attack can significantly impact additional products beyond Service Delivery Platform itself.
Why It Matters
Oracle describes the vulnerability as "easily exploitable," allowing a low-privileged attacker with network access to compromise the platform. Successful exploitation can result in a complete takeover of Service Delivery Platform, with high impact to confidentiality, integrity, and availability. The scope change (S:C) means the blast radius may extend to other connected products, raising the stakes for any environment exposing T3 or IIOP interfaces to attackers.
What's Vulnerable
- Product: Oracle Service Delivery Platform (Oracle Fusion Middleware)
- Component: Messaging Enabler
- Affected versions: 12.2.1.4.0 and 14.1.2.0.0
- Attack surface: Network access via the T3 and IIOP protocols
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Administrators running the affected versions (12.2.1.4.0 and 14.1.2.0.0) should apply the fixes referenced in the Oracle Critical Patch Update Advisory for July 2026. This CVE record does not indicate confirmation of active exploitation.