Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-60389: Oracle Fusion Middleware Messaging Enabler can be taken over via HTTP

CVE-2026-60389 CVE-2026-60389
Summary

The Messaging Enabler component of Oracle Fusion Middleware's Service Delivery Platform has a security flaw that can be exploited by anyone with access to the platform's HTTP connection. This could allow an attacker to take control of the Service Delivery Platform, potentially affecting other connected products. Oracle recommends updating to a fixed version to address this vulnerability.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
oracle corporation service delivery platform 12.2.1.4.0
Original title
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily explo...
Original description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
mitre CVSS3.1 10.0
Published: 21 Jul 2026 · Updated: 25 Jul 2026 · First seen: 24 Jul 2026