CVE-2026-82997

9.9

Oracle · Service Delivery Platform

A critical vulnerability in the Oracle Service Delivery Platform Messaging Enabler allows low privileged, network-based attackers to achieve full system takeover via T3 or IIOP protocols.

Executive summary

An easily exploitable, critical vulnerability exists in Oracle Service Delivery Platform that allows remote attackers to gain unauthorized control over the system.

Vulnerability

This vulnerability affects the Messaging Enabler component and allows a low privileged, authenticated attacker with network access to compromise the platform using T3 or IIOP protocols. The flaw supports scope changes, meaning a compromise of this component may result in the takeover of additional integrated products.

Business impact

The vulnerability carries a CVSS score of 9.9, indicating a critical risk to confidentiality, integrity, and availability. Successful exploitation allows an attacker to gain full control over the Service Delivery Platform, potentially leading to unauthorized data exfiltration, service disruption, and lateral movement into other connected infrastructure.

Remediation

Immediate Action: Apply the September 2026 Critical Security Patch Update provided by Oracle to address this issue.

Proactive Monitoring: Review network access logs for suspicious activity involving T3 or IIOP traffic and monitor for unauthorized administrative actions within the Messaging Enabler component.

Compensating Controls: Restrict network access to the affected ports and protocols to only known, trusted sources and implement Web Application Firewall (WAF) filtering where applicable.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical CVSS score of 9.9 and the potential for full system takeover, organizations must prioritize the application of the September 2026 Critical Security Patch Update. Immediate patching is the only effective way to mitigate the risk posed by this vulnerability.

More Oracle CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Analyst report updated
  5. Published in the daily brief critical section

Sources