Junglewise Threat Intelligence

CVE-2026-60318: Oracle Data Integrator information disclosure in Patchset Assistant

CVE-2026-60318 · Severity: low · CVSS 3.3 · Published 2026-07-21

Technologies: Oracle Data Integrator. Vendors: Oracle.

Executive brief

Oracle Data Integrator, a tool used for high-performance data movement and transformation, contains a security vulnerability in its Patchset Assistant component. An attacker with existing low-level access to the server where the software is installed could exploit this flaw to view sensitive internal data. While the risk is limited to data exposure rather than full system control, it could lead to the unauthorized disclosure of business information.

Technical details

An information disclosure vulnerability exists in the Patchset Assistant component of Oracle Data Integrator (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is categorized as easily exploitable and requires the attacker to have local logon credentials to the infrastructure where the software executes. Successful exploitation allows a low-privileged attacker to gain unauthorized read access to a subset of data accessible by the Oracle Data Integrator service. The vulnerability is tracked as CVE-2026-60318 and was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Data Integrator 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats