CVE-2026-60865 Overview
CVE-2026-60865 affects the Oracle Service Delivery Platform, a component of Oracle Fusion Middleware. The flaw resides in the Messaging Enabler component and is classified under [CWE-284] Improper Access Control. Supported versions 14.1.2.0.0 and 12.2.1.4.0 are impacted.
A high-privileged attacker with network access over HTTP can exploit the weakness to compromise confidentiality across multiple Oracle products. The vulnerability carries a scope change, meaning successful exploitation can impact resources beyond the vulnerable component. Oracle disclosed the issue in the August 2026 Critical Patch Update.
Critical Impact
Successful exploitation grants unauthorized access to critical data or complete access to all Service Delivery Platform accessible data, with scope-change impact reaching adjacent Oracle products.
Affected Products
- Oracle Service Delivery Platform 14.1.2.0.0
- Oracle Service Delivery Platform 12.2.1.4.0
- Oracle Fusion Middleware — Messaging Enabler component
Discovery Timeline
- 2026-08-18 - CVE-2026-60865 published to NVD
- 2026-08-20 - Last updated in NVD database
Technical Details for CVE-2026-60865
Vulnerability Analysis
The vulnerability is located in the Messaging Enabler component of the Oracle Service Delivery Platform. It stems from improper access control, categorized as [CWE-284]. An authenticated attacker with elevated privileges can leverage HTTP requests to bypass access restrictions within the messaging subsystem.
Oracle's advisory notes that while the flaw resides in the Service Delivery Platform, exploitation causes a scope change. Attacks originating from the vulnerable component can reach data owned by other Oracle products in the same deployment. The impact is limited to confidentiality; there is no direct integrity or availability effect.
EPSS data reports a probability of 0.381% at the 31.4 percentile, and no public exploit is currently tracked. Oracle has not disclosed granular technical details beyond the security alert.
Root Cause
The root cause is improper enforcement of access control within the Messaging Enabler component. Authenticated requests over HTTP are not adequately restricted, allowing a high-privileged account to reach data or interfaces that should remain isolated. The scope change indicates trust boundaries between the Service Delivery Platform and adjacent Oracle services are not enforced.
Attack Vector
Exploitation requires network access to the platform's HTTP interface and valid high-privileged credentials. No user interaction is required. An attacker sends crafted HTTP requests to Messaging Enabler endpoints, then leverages the access-control weakness to read data from the Service Delivery Platform or from products sharing its trust context. See the Oracle Security Alert for technical details.
Detection Methods for CVE-2026-60865
Indicators of Compromise
- Unusual HTTP requests to Messaging Enabler endpoints from high-privileged service or administrative accounts.
- Access patterns where a Service Delivery Platform account reads objects belonging to other Oracle Fusion Middleware products.
- Authentication events for privileged accounts from unexpected source IP ranges or at atypical hours.
Detection Strategies
- Enable and centralize Oracle Fusion Middleware audit logging for the Messaging Enabler component and correlate against baseline access patterns.
- Alert on privileged account activity that crosses application boundaries within the Fusion Middleware stack.
- Baseline HTTP request volume and endpoints per privileged account, and flag deviations for review.
Monitoring Recommendations
- Forward Oracle Fusion Middleware and Service Delivery Platform logs to a centralized SIEM or data lake for cross-product correlation.
- Monitor outbound data flows from Service Delivery Platform nodes to detect unauthorized bulk data retrieval.
- Review privileged account inventories quarterly and revoke unused or excessive entitlements to Messaging Enabler.
How to Mitigate CVE-2026-60865
Immediate Actions Required
- Apply the fixes from the Oracle August 2026 Critical Patch Update to affected Service Delivery Platform deployments.
- Inventory all Oracle Fusion Middleware 14.1.2.0.0 and 12.2.1.4.0 instances running the Messaging Enabler component.
- Rotate credentials for high-privileged Service Delivery Platform accounts and review recent access logs for anomalies.
Patch Information
Oracle addressed CVE-2026-60865 in the August 2026 Critical Patch Update. Administrators should reference the Oracle Security Alert for patch identifiers, applicability, and installation guidance for versions 14.1.2.0.0 and 12.2.1.4.0.
Workarounds
- Restrict HTTP access to Messaging Enabler endpoints using network segmentation and firewall allowlists until patches are applied.
- Limit high-privileged accounts on the Service Delivery Platform and enforce multi-factor authentication for administrative access.
- Enable verbose auditing on the Messaging Enabler component to detect exploitation attempts pending remediation.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

