Executive brief
A critical vulnerability has been identified in Oracle Data Integrator, a tool used for high-performance data movement and transformation. An unauthenticated attacker can exploit this flaw over the network to gain full control of the system. This could lead to the complete theft or destruction of sensitive corporate data and may allow the attacker to pivot to other connected business systems.
Technical details
This vulnerability exists within the Rest Service component of Oracle Data Integrator (versions 12.2.1.4.0 and 14.1.2.0.0). It is classified as easily exploitable, requiring no authentication or user interaction (AV:N/AC:L/PR:N/UI:N). The flaw allows for a complete takeover of the application and carries a 'Scope Change' (S:C) designation, meaning an exploit can impact resources beyond the immediate security scope of Oracle Data Integrator. Successful exploitation results in total loss of confidentiality, integrity, and availability. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation steps.
Affected products
- Oracle Data Integrator 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory