CVE-2026-60381
Oracle · Service Delivery Platform
A critical vulnerability in Oracle Service Delivery Platform allows an authenticated attacker to achieve a complete system takeover via the Messaging Enabler component.
Executive summary
A critical vulnerability in Oracle Service Delivery Platform allows authenticated attackers to gain full control over the system.
Vulnerability
This vulnerability resides in the Messaging Enabler component and is easily exploitable by a low-privileged attacker. Using network access via T3 or IIOP protocols, the attacker can execute a full system takeover, potentially impacting other associated products due to a scope change.
Business impact
With a CVSS score of 9.9, this vulnerability poses an existential risk to the affected infrastructure. A full system takeover allows an attacker to bypass all security controls, potentially leading to total data loss, complete service outages, and the compromise of all information managed by or accessible to the Service Delivery Platform.
Remediation
Immediate Action: Install the official security updates released by Oracle in the July 2026 CPU cycle to remediate this vulnerability.
Proactive Monitoring: Monitor for any signs of unauthorized administrative activity or unexpected changes to system configurations within the Messaging Enabler.
Compensating Controls: If patching is delayed, isolate the Service Delivery Platform from external networks and strictly control internal access to T3 and IIOP ports.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability is highly severe and must be prioritized for immediate remediation. Administrators should ensure that all affected Service Delivery Platform instances are patched promptly to prevent the risk of a full system compromise.