Executive brief
Oracle Data Integrator is a data integration platform used to build and manage ETL (extract, transform, load) workflows within Oracle Fusion Middleware. An unauthenticated attacker on the network can exploit a vulnerability in the Console/Repository Explorer component to gain full control of the system, potentially exposing sensitive data, corrupting data pipelines, and disrupting critical business processes.
Technical details
This vulnerability in Oracle Data Integrator's Console/Repository Explorer component allows an unauthenticated attacker with network access to submit a specially crafted HTTP request and achieve remote code execution. No authentication is required and user interaction is not needed. The attack is easily exploitable due to low attack complexity. Successful exploitation results in complete takeover of the Oracle Data Integrator instance, granting the attacker full read, write, and execution privileges. Patches should be applied to affected versions 12.2.1.4.0 and 14.1.2.0.0 as soon as they become available.
Affected products
- Oracle Data Integrator 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed: CVE-2026-83232 published