A maximum-severity (CVSS 10.0) flaw in Oracle Service Delivery Platform's Messaging Enabler component lets an unauthenticated, remote attacker fully take over the product over HTTP.
What Is It
CVE-2026-60389 is a vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware, specifically the Messaging Enabler component. Oracle describes it as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful exploitation can result in complete takeover of the product. It carries a CVSS 3.1 Base Score of 10.0 (CRITICAL) with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H.
Why It Matters
This is a worst-case scenario: no authentication, no user interaction, low attack complexity, and network reachability over HTTP. The CVSS breakdown reflects full impact to confidentiality, integrity, and availability. Critically, the scope is Changed: while the vulnerability resides in Service Delivery Platform, Oracle notes that attacks may significantly impact additional products beyond the vulnerable component itself. That combination of trivial exploitability and cross-component blast radius makes it a top-priority remediation.
Note: The supplied source material contains no CISA KEV entry for this CVE, so active exploitation is not confirmed by KEV at this time.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Service Delivery Platform (Oracle Fusion Middleware)
- Component: Messaging Enabler
- Affected versions: 12.2.1.4.0 and 14.1.2.0.0
Patch Status
The vulnerability was published on 2026-07-21 with a status of "Received." The sole reference is Oracle's July 2026 Critical Patch Update advisory. Organizations running the affected versions should apply the fixes distributed through the Oracle Critical Patch Update as their required remediation. No additional required-action guidance beyond the Oracle CPU is present in the supplied source material.
Sources
- Oracle Critical Patch Update Advisory (July 2026), https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60389 (source: [email protected])