Junglewise Threat Intelligence

CVE-2026-47056: Oracle Data Integrator remote compromise in Rest Service

CVE-2026-47056 · Severity: critical · CVSS 10 · Published 2026-07-21

Technologies: Oracle Data Integrator. Vendors: Oracle.

Executive brief

A critical vulnerability has been identified in Oracle Data Integrator, a tool used for high-performance data movement and transformation. An unauthenticated attacker can exploit this flaw over the network to gain full control of the system. This could lead to the complete theft or destruction of sensitive corporate data and may allow the attacker to pivot to other connected business systems.

Technical details

This vulnerability exists within the Rest Service component of Oracle Data Integrator (versions 12.2.1.4.0 and 14.1.2.0.0). It is classified as easily exploitable, requiring no authentication or user interaction (AV:N/AC:L/PR:N/UI:N). The flaw allows for a complete takeover of the application and carries a 'Scope Change' (S:C) designation, meaning an exploit can impact resources beyond the immediate security scope of Oracle Data Integrator. Successful exploitation results in total loss of confidentiality, integrity, and availability. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation steps.

Affected products

  • Oracle Data Integrator 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats