External risk intelligence

Oracle Fusion Middleware Service Delivery Platform Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-60381

The vulnerability affects a messaging component in middleware. While it relies on T3 and IIOP protocols which are network-accessible, these protocols are typically used for internal application server communication rather than direct public-facing exposure in standard deployments.

Oracle Service Delivery Platform

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability affects Oracle Fusion Middleware's Service Delivery Platform, specifically its messaging component. An attacker with limited privileges could exploit this through network access to compromise the platform, potentially impacting other connected products and leading to a full takeover.

  • Remote attacker gains platform control.
  • Critical issue: broad impact on middleware.
  • Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker with network access could exploit this vulnerability by targeting the Messaging Enabler component within Oracle Fusion Middleware's Service Delivery Platform. This could lead to a full takeover of the Service Delivery Platform, potentially impacting other products.

  • Attacker has network access.
  • T3 or IIOP protocols are used.
  • Complete takeover of the platform.

Live Threat

Current exploitation, exposure, and threat context

A low-privileged attacker with network access via T3 or IIOP could potentially take over the Service Delivery Platform. When supported, this vulnerability could impact additional products beyond the Service Delivery Platform itself, leading to significant consequences.

  • Service Delivery Platform and related products.
  • Network access via T3 or IIOP protocols.
  • Complete takeover of the affected platform.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Service Delivery Platform component within Oracle Fusion Middleware is affected by this critical vulnerability. Given the nature of the affected component and its potential to impact other products, application owners and infrastructure teams should collaborate to identify all instances of the Service Delivery Platform. The initial priority is to determine its reachability, business criticality, and confirm the accountable owner before planning remediation.

  • Application and infrastructure teams own the issue.
  • Verify Service Delivery Platform instances and criticality.
  • Plan remediation based on confirmed ownership and risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Fusion Middleware Service Delivery Platform?

It is a middleware product designed to manage and orchestrate service delivery across complex telecommunications and enterprise environments. It serves as a central hub for processing and routing information. The specific Messaging Enabler component acts as a bridge for communication protocols, allowing different software modules to exchange data seamlessly within the infrastructure.

How does CVE-2026-60381 affect the system?

This vulnerability is a critical security flaw that allows an unauthorized party to gain full control over the Service Delivery Platform. Because of its nature, it can also impact other interconnected products integrated with the platform. It essentially represents a total breach of the platform's confidentiality, integrity, and availability, allowing a low-privileged user to execute unauthorized actions.

Does this bug trigger from any network connection?

No, the vulnerability specifically requires network access via the T3 or IIOP protocols to reach the Messaging Enabler component. If your network configuration blocks these specific protocols or restricts access to the platform to trusted segments, the attack path is not open. It does not trigger via common web protocols like HTTP or HTTPS.

Is my instance at risk according to Halo Surface Signal?

Halo Surface Signal notes that while T3 and IIOP are necessary for the attack, they are typically used for internal server-to-server communication. Therefore, direct exposure to the public internet is less common than for standard web applications. You should focus your investigation on instances that allow these protocols across internal network boundaries where attackers might already have a foothold.

What steps should I take if I use this software?

Start by identifying all active deployments of the Service Delivery Platform within your infrastructure. Once you have an inventory, verify which instances are reachable over your network via T3 or IIOP. After documenting your assets and confirming ownership, coordinate with your infrastructure team to prioritize these systems for security updates and harden network access controls to limit potential movement.

References