Junglewise Threat Intelligence

CVE-2026-35262: Oracle Data Integrator improper access control in Market Place

CVE-2026-35262 · Severity: high · CVSS 8.3 · Published 2026-06-17

Technologies: Oracle Data Integrator. Vendors: Oracle.

Executive brief

A vulnerability in Oracle Data Integrator's Market Place component allows an authorized user with low-level permissions to gain broad access to the system. An attacker could view, modify, or delete sensitive business data and disrupt data integration services. This could lead to significant data breaches or operational downtime for organizations relying on this middleware for data movement and transformation.

Technical details

An improper access control vulnerability (CWE-284) exists in the Market Place component of Oracle Data Integrator. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to perform unauthorized creation, deletion, or modification of critical data, as well as gain complete read access to all data accessible by the application. Additionally, the vulnerability can be used to cause a partial denial of service. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.

Affected products

  • Oracle Data Integrator 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References

Related threats