A critical flaw in Oracle Fusion Middleware's Service Delivery Platform lets a low-privileged attacker with network access fully take over the product and reach beyond it into other components.
What Is It
CVE-2026-82998 is a vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware, specifically in the Messaging Enabler component. Oracle describes it as easily exploitable: an attacker needs only low privileges and network access over the T3 or IIOP protocols to compromise Service Delivery Platform. No user interaction is required.
Successful exploitation results in takeover of Service Delivery Platform. The vulnerability carries a scope change, meaning attacks may significantly impact additional products beyond the vulnerable component itself.
The CVE was published on 2026-09-15 by Oracle ([email protected]) and currently sits in "Received" status at NVD.
Why It Matters
The CVSS 3.1 base score is 9.9 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. That breaks down to network attack vector, low attack complexity, low privileges required, no user interaction, changed scope, and high impact to confidentiality, integrity, and availability. The exploitability subscore is 3.1 and the impact subscore is 6.0.
The 9.9 rating, just shy of the maximum, is driven by the combination of a trivially reachable network path and the scope change that carries impact into adjacent products. T3 and IIOP are Oracle middleware protocols that may, in some deployments, be reachable from networks operators did not intend to expose them to, which could widen the practical attack surface. Neither Oracle's advisory nor the NVD record quantifies how common such exposure is in the field.
Note: as of publication, CVE-2026-82998 is not listed in CISA's Known Exploited Vulnerabilities catalog (https://www.cisa.gov/known-exploited-vulnerabilities-catalog), so there is no federally confirmed active exploitation and no BOD 22-01 remediation deadline attached to it. Defenders should re-check the catalog, which CISA updates on a rolling basis, before treating that status as settled.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Service Delivery Platform (Oracle Fusion Middleware)
- Component: Messaging Enabler
- Affected versions: 12.2.1.4.0 and 14.1.2.0.0
Patch Status
Oracle published this issue as part of its security alerts program. The advisory at oracle.com/security-alerts/cspusep2026.html is the authoritative source for fix availability and patch guidance. Beyond that vendor advisory, no external body has issued a required-action deadline or mandated remediation timeline for this CVE.
Sources
- NVD, CVE-2026-82998: https://nvd.nist.gov/vuln/detail/CVE-2026-82998
- Oracle Security Alert (CSPU Sep 2026): https://www.oracle.com/security-alerts/cspusep2026.html
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog