Cyber & AI intelligence
Wasteland.
Briefs indexed2663
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-82999 2026-09-15

CVE-2026-82999: Critical Takeover Flaw in Oracle Service Delivery Platform

"The editorial notes arrived truncated mid-sentence in both fields (`factual_fidelity` ends at "but the", `hedging` ends at the opening quote of the replacement text), so I applied the hedging pass to the three absolute…"

The editorial notes arrived truncated mid-sentence in both fields (factual_fidelity ends at "but the", hedging ends at the opening quote of the replacement text), so I applied the hedging pass to the three absolute claims I could identify and, for factual fidelity, corrected the one claim that contradicts the article's own "NVD status: Received" note; CVSS attribution. Send the full notes if you want the intended wording instead.

CVE-2026-82999: Critical Takeover Flaw in Oracle Service Delivery Platform

Oracle disclosed a critical (CVSS 9.9) vulnerability in the Messaging Enabler component of Oracle Service Delivery Platform that could allow a low-privileged remote attacker to take over the product and affect adjacent systems.

What Is It

CVE-2026-82999 is a vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware, specifically the Messaging Enabler component. Oracle describes it as easily exploitable: an attacker with low privileges and network access over HTTP can compromise Service Delivery Platform without any user interaction. According to Oracle, successful exploitation can result in takeover of Service Delivery Platform.

The CVSS 3.1 base score is 9.9 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network attack vector, low complexity, low privileges required, no user interaction, and high impact to confidentiality, integrity, and availability. The score and vector are supplied by Oracle as CNA and appear on the NVD entry for CVE-2026-82999; NVD has not yet published its own analysis.

Why It Matters

Two details drive the severity. First, the scope is changed (S:C): Oracle states that while the vulnerability resides in Service Delivery Platform, attacks may significantly impact additional products. A compromise may not stay contained to the vulnerable component.

Second, the barrier to entry is low. The attacker needs only network access over HTTP and a low-privileged account; no admin credentials, no victim interaction, no complex preconditions. Combined with full confidentiality, integrity, and availability impact, that combination is what pushes the score into the top of the critical range rather than leaving it a scope-unchanged remote flaw.

What's Vulnerable

No other versions are listed as affected in the supplied advisory data.

Patch Status

The advisory data points to an Oracle security alert page dated September 2026 (cspusep2026.html). Note that this falls outside Oracle's quarterly Critical Patch Update cycle, which ships in January, April, July, and October; so this appears to be an off-cycle security alert rather than a CPU release, and the next scheduled CPU is October 2026. Operators of the affected 12.2.1.4.0 and 14.1.2.0.0 releases should verify the referenced alert against Oracle's security alerts index and apply the fix identified there; if the patch is not yet available off-cycle, plan for the October 2026 CPU.

The CVE record was published 2026-09-15 and carries NVD vulnerability status Received, meaning NVD enrichment (including CPE matching) is not yet complete. As of this writing, CVE-2026-82999 does not appear in the CISA Known Exploited Vulnerabilities Catalog, so there is no confirmation of active exploitation and no KEV-mandated remediation deadline at this time. Absence from KEV is not evidence of low risk; given the 9.9 score and scope change, treat this as priority patching regardless.

Sources