External risk intelligence

Oracle Fusion Middleware Service Delivery Platform Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60386

The vulnerability affects a Service Delivery Platform, which is typically deployed as an internet-facing gateway or service to facilitate external communications. Because it is accessible via HTTP and supports unauthenticated access, it is commonly exposed as an edge service, making it likely to be reachable from the internet in standard deployments.

Missing Authentication

Oracle Service Delivery Platform

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Fusion Middleware's Service Delivery Platform, specifically affecting its messaging capabilities. This issue could allow an attacker to take complete control of the platform, impacting confidentiality, integrity, and availability. The main concern is to confirm if our organization utilizes this specific Oracle product and version.

  • Unauthenticated attackers can gain full control.
  • Critical impact on platform availability and data.
  • Confirm if this Oracle product is in use.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by sending network requests over HTTP to the Service Delivery Platform. This could lead to a full takeover of the platform.

  • Attacker needs network access.
  • Attacker triggers by sending HTTP requests.
  • Risk is complete platform takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access to compromise the Oracle Fusion Middleware Service Delivery Platform, potentially leading to a complete takeover of the platform. This could affect the availability and integrity of services managed by the platform, as well as the confidentiality of any data processed by it.

  • Service Delivery Platform data and services.
  • Unauthenticated network access via HTTP.
  • Complete takeover of the platform.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Oracle Fusion Middleware's Service Delivery Platform, accessible via HTTP without authentication, could allow an attacker to take over the platform. The first step is to identify all instances of the affected technology, confirm their reachability and business criticality, and then assign ownership for risk-based remediation.

  • Platform or application owners should manage this.
  • Verify external network exposure and criticality.
  • Plan vendor-coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Oracle Fusion Middleware Service Delivery Platform?

This platform acts as a bridge for communication services within enterprise environments. It helps manage and route messaging traffic between different systems. Organizations typically use it to facilitate data exchange across complex networks, making it a central point for service delivery.

What does this CVE-2026-60386 vulnerability mean?

This is a security flaw that allows a remote user to gain complete control over the platform. Because the system fails to properly verify the identity of the requester, an unauthorized party can execute commands as if they were a legitimate administrator, leading to full system compromise.

How can an attacker trigger this vulnerability?

The vulnerability is triggered by sending specially crafted HTTP requests to the Messaging Enabler component of the platform. No interaction from a logged-in user or special permissions are needed. It does not occur through physical access, offline configuration files, or non-network interactions.

Do I need to worry if my system is internal?

Halo Surface Signal indicates that this platform is often used as an edge service to facilitate external communications, which makes it a high-priority target for internet-based attacks. If your instance is reachable from the public internet, it faces a significantly higher risk than a system strictly isolated within an internal network.

What should I do if I run this technology?

First, conduct an inventory to find all instances of the affected versions, 12.2.1.4.0 and 14.1.2.0.0. Once identified, evaluate their network placement and business purpose. After confirming where the software is running, prepare to apply official vendor security updates and monitor official channels for specific remediation instructions.

References