A critical (CVSS 9.8) vulnerability in Oracle Fusion Middleware's Service Delivery Platform allows an unauthenticated attacker to fully compromise the product over the network via HTTP.
What Is It
CVE-2026-60386 is a critical flaw in the Service Delivery Platform product of Oracle Fusion Middleware, specifically within the Messaging Enabler component. Oracle describes it as an easily exploitable vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise the Service Delivery Platform. A successful attack can result in a complete takeover of the platform.
The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting high impact to confidentiality, integrity, and availability.
Why It Matters
This vulnerability combines the worst-case exploitability and impact characteristics: it requires no authentication, no privileges, and no user interaction, and is reachable remotely over the network with low attack complexity. Because a successful attack results in full takeover of the Service Delivery Platform, with high confidentiality, integrity, and availability impact, an exposed instance represents a direct path to complete compromise. The 3.9 exploitability sub-score is the maximum possible, underscoring how easily this can be leveraged.
What's Vulnerable
The affected product is Oracle Corporation's Service Delivery Platform (Oracle Fusion Middleware), component Messaging Enabler. The supported versions confirmed affected are:
- 12.2.1.4.0
- 14.1.2.0.0
Patch Status
Oracle addressed this issue in its July 2026 Critical Patch Update. Organizations running the affected versions should consult Oracle's advisory and apply the corresponding Critical Patch Update fixes. No CISA KEV entry confirming active exploitation was supplied for this CVE at the time of writing.