CVE-2026-82997
9.9Oracle · Service Delivery Platform
A critical vulnerability in the Oracle Service Delivery Platform Messaging Enabler allows low privileged, network-based attackers to achieve full system takeover via T3 or IIOP protocols.
Executive summary
An easily exploitable, critical vulnerability exists in Oracle Service Delivery Platform that allows remote attackers to gain unauthorized control over the system.
Vulnerability
This vulnerability affects the Messaging Enabler component and allows a low privileged, authenticated attacker with network access to compromise the platform using T3 or IIOP protocols. The flaw supports scope changes, meaning a compromise of this component may result in the takeover of additional integrated products.
Business impact
The vulnerability carries a CVSS score of 9.9, indicating a critical risk to confidentiality, integrity, and availability. Successful exploitation allows an attacker to gain full control over the Service Delivery Platform, potentially leading to unauthorized data exfiltration, service disruption, and lateral movement into other connected infrastructure.
Remediation
Immediate Action: Apply the September 2026 Critical Security Patch Update provided by Oracle to address this issue.
Proactive Monitoring: Review network access logs for suspicious activity involving T3 or IIOP traffic and monitor for unauthorized administrative actions within the Messaging Enabler component.
Compensating Controls: Restrict network access to the affected ports and protocols to only known, trusted sources and implement Web Application Firewall (WAF) filtering where applicable.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical CVSS score of 9.9 and the potential for full system takeover, organizations must prioritize the application of the September 2026 Critical Security Patch Update. Immediate patching is the only effective way to mitigate the risk posed by this vulnerability.
More Oracle CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Analyst report updated
- Published in the daily brief critical section
Sources
- Oracle Advisory Vendor advisory