External risk intelligence

Oracle Fusion Middleware Service Delivery Platform Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60385

This vulnerability affects the Messaging Enabler in Oracle Fusion Middleware, which uses T3 and IIOP protocols. These components are frequently deployed as internet-facing or edge services to enable external connectivity, making them reachable in many standard deployment patterns.

Missing Authentication

Oracle Service Delivery Platform

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Fusion Middleware's Service Delivery Platform, specifically within its Messaging Enabler component. This flaw, which can be exploited remotely by an unauthenticated attacker, could lead to a complete takeover of the affected platform, impacting confidentiality, integrity, and availability.

  • Unauthenticated attackers can take over the platform.
  • Critical vulnerability in Oracle Fusion Middleware.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could compromise Oracle Fusion Middleware's Service Delivery Platform by sending specially crafted network requests. Since no authentication is needed and the attacker only needs network access, they could exploit the Messaging Enabler component to gain complete control of the platform.

  • Requires network access without authentication.
  • Targets the Messaging Enabler component.
  • Results in full platform takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to take control of the Service Delivery Platform when it is exposed via network protocols like T3 or IIOP. Such an attacker could then access, modify, or disable the platform's services and data.

  • Service Delivery Platform.
  • Network access via T3, IIOP.
  • Full platform takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Oracle Fusion Middleware Service Delivery Platform's Messaging Enabler component is vulnerable, potentially impacting systems exposed via T3 or IIOP protocols. Initial actions should focus on identifying all instances of this technology, assessing their network reachability and business criticality, pinpointing the accountable system or application owners, and then prioritizing remediation efforts based on the identified risk.

  • Service Delivery Platform owners should lead remediation.
  • Verify external reachability and business criticality first.
  • Plan coordinated updates during maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Oracle Fusion Middleware Service Delivery Platform?

It is a component of the Oracle Fusion Middleware suite that includes a Messaging Enabler. This specific platform facilitates communication services by managing data exchange, and it is the product affected by the security issue tracked in CVE-2026-60385 for versions 12.2.1.4.0 and 14.1.2.0.0.

How is CVE-2026-60385 categorized?

This is a critical security vulnerability with a CVSS 3.1 base score of 9.8. It allows an unauthenticated attacker to achieve a full system takeover, meaning the unauthorized party gains complete control over the confidentiality, integrity, and availability of the affected Service Delivery Platform.

What triggers the vulnerability in this platform?

The flaw is triggered when an attacker sends specially crafted network requests to the Messaging Enabler component. This does not require the attacker to have valid user credentials or pre-existing authentication, and it functions specifically through network access via the T3 and IIOP protocols.

Why is this vulnerability considered a relevant risk?

According to the Halo Surface Signal, this vulnerability is likely to pose a risk because the Messaging Enabler is often deployed as an edge service or internet-facing component. The use of T3 and IIOP protocols for these services frequently makes them reachable in many standard organizational network deployment patterns.

How should administrators respond to this security issue?

Owners should first identify all active instances of the Service Delivery Platform. Assess the business criticality and external network reachability of these instances. Once the risk is understood, prioritize the application of official updates during scheduled maintenance windows to secure the Messaging Enabler component.

References