External risk intelligence

Oracle Service Delivery Platform Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-60389

The vulnerability affects a Service Delivery Platform, which is commonly deployed as an internet-facing gateway or service endpoint to facilitate network communications. As it is accessible via HTTP and explicitly described as being exploitable by an unauthenticated network user, it is frequently exposed to the public internet in standard deployment patterns.

Missing Authentication

Oracle Service Delivery Platform

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability impacts Oracle Fusion Middleware's Service Delivery Platform, an easily exploitable issue that allows an unauthenticated attacker with network access to potentially take over the platform and significantly impact other connected products.

  • Unauthenticated network access compromises the platform.
  • It enables significant disruption to connected systems.
  • Confirm relevance and assess potential business impact.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker with network access can exploit this vulnerability in Oracle Fusion Middleware's Service Delivery Platform. The attacker can reach the vulnerable component via HTTP, potentially leading to a complete takeover of the platform and impacting other connected products.

  • Network access required.
  • HTTP can trigger the vulnerability.
  • Platform takeover is possible.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via HTTP could compromise the Service Delivery Platform. This could lead to the takeover of the platform, potentially impacting other products due to a scope change. The vulnerability has a CVSS 3.1 Base Score of 10.0, indicating critical impacts on confidentiality, integrity, and availability.

  • Service Delivery Platform.
  • Network access via HTTP.
  • Takeover of the platform.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Oracle Fusion Middleware's Service Delivery Platform, exploitable remotely via HTTP, requires immediate attention from infrastructure and platform teams responsible for its deployment. The first step is to identify all instances of the affected product, determine their network exposure and business criticality, and then locate the accountable owner to plan remediation.

  • Platform and infrastructure teams own this.
  • Verify network reachability and business impact.
  • Plan remediation during the next maintenance window.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Oracle Service Delivery Platform?

The Service Delivery Platform is a component within Oracle Fusion Middleware designed to manage and facilitate communications. It acts as a messaging enabler, allowing different services or systems to exchange data. Organizations use this platform to streamline how information flows between various middleware applications and external endpoints.

What does CVE-2026-60389 mean for my security?

This CVE describes a critical security weakness that allows an unauthorized person to gain full control of the Messaging Enabler component. Because this is a severe flaw, it essentially permits an attacker to bypass standard login requirements, potentially manipulating the platform's data or service operations.

How does an attacker trigger this vulnerability?

An attacker triggers this flaw by sending specific, crafted HTTP requests to the Service Delivery Platform over a network. Importantly, the attacker does not need a valid user account or password to initiate the attack. If the component cannot be reached over the network via HTTP, it cannot be targeted by this specific method.

Is my system at risk if it is not on the public internet?

Halo Surface Signal indicates that while these platforms are frequently deployed as internet-facing gateways, any system accessible over a network is potentially at risk. If your instance is isolated to an internal network, it is less accessible to external attackers, though you should still verify if your internal network traffic could reach the platform.

What should I do if I am running this software?

First, create an inventory of all instances of the affected versions, specifically 12.2.1.4.0 and 14.1.2.0.0. Once identified, evaluate the network accessibility of each instance and determine its role in your environment. Reach out to your infrastructure team to prioritize these assets for remediation during your next planned maintenance window.

References