A CVSS 9.9 vulnerability in the Messaging Enabler component of Oracle Service Delivery Platform lets a low-privileged attacker with network access take over the product and reach beyond it into adjacent systems.
What Is It
CVE-2026-82997 is a vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware, specifically in the Messaging Enabler component. Oracle describes it as easily exploitable: an attacker needs only low privileges and network access over the T3 or IIOP protocols, with no user interaction required. Successful exploitation results in full takeover of Service Delivery Platform.
The CVSS 3.1 base score is 9.9 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The record was published 2026-09-15 by Oracle's security alert channel and currently carries NVD status "Received."
Why It Matters
Two details drive the severity. First, the scope is changed; Oracle notes that while the flaw resides in Service Delivery Platform, attacks may significantly impact additional products. A compromise does not stay contained to the vulnerable component.
Second, the impact is total across confidentiality, integrity, and availability, all rated HIGH. Combined with low attack complexity and only low privileges required, this is a realistic path from a minimally authenticated foothold to full product takeover.
The exposure runs over T3 and IIOP, the internal remoting protocols associated with Oracle middleware deployments. Any environment where those listeners are reachable from untrusted or semi-trusted network segments widens the attack surface considerably.
There is no CISA KEV entry for this CVE in the supplied data, so active exploitation is not currently confirmed.
What's Vulnerable
Per Oracle, the affected supported versions of Service Delivery Platform are:
- 12.2.1.4.0
- 14.1.2.0.0
The vulnerable component is Messaging Enabler. No CPE match data is present in the NVD record.
Patch Status
The supplied data contains no explicit remediation instruction or required-action deadline. The sole reference is Oracle's security alert page for the relevant advisory cycle, which is the authoritative source for fixed versions and patch availability. Administrators running either affected version should consult that advisory directly.
Sources
- NVD, CVE-2026-82997 (source:
[email protected], published 2026-09-15) - Oracle Security Alert; https://www.oracle.com/security-alerts/cspusep2026.html