Sceawere
Vulnerability Detail
CVE-2026-60999Updated Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Data Integrator RCE Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Data Integrator
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-07-21T22:18:32.240Z",
"pubdate": "2026-07-21T22:18:32.240Z",
"executiveSummary": "A critical security vulnerability has been identified in the Oracle Data Integrator component of Oracle Fusion Middleware, specifically within the Rest Service.\nThe vulnerability allows an unauthenticated, remote attacker to achieve a complete system compromise via network access over HTTPS.\nThe flaw carries a CVSS 3.1 Base Score of 9.8, reflecting its severe impact on the Confidentiality, Integrity, and Availability of the targeted system.\nExploitation does not require user interaction or pre-existing privileges, making it highly accessible to external threat actors.\nGiven that successful exploitation leads to full takeover, the risk to enterprise operations is extreme, necessitating immediate remediation efforts.\nThe vulnerability resides in the Rest Service layer, which acts as a primary attack surface for remote code execution or unauthorized command injection.",
"technicalDetails": "The vulnerability exists within the Rest Service component of Oracle Data Integrator version 14.1.2.0.0. The underlying issue stems from a failure to properly sanitize or authorize inputs processed through the REST API endpoints exposed by the middleware.\nBecause the service accepts and processes requests without requiring prior authentication, an attacker can submit specially crafted HTTP requests over HTTPS to trigger the flaw.\nThe attack flow initiates with the attacker identifying the target endpoint on the network. By leveraging the lack of authentication, the attacker can submit a payload directly to the Rest Service. The vulnerability allows for the execution of arbitrary commands or code in the context of the application server process.\nTechnical exploitation typically involves injecting malicious serialized objects or command strings into the parameters handled by the Rest Service. Because the service lacks sufficient integrity checks on these inputs, the application executes the injected code with the privileges of the Oracle Data Integrator process.\nThis behavior results in a total loss of the Confidentiality, Integrity, and Availability of the host system. Post-exploitation, an attacker can pivot within the network, access sensitive integration data, modify or delete repository configurations, or maintain persistent access to the environment.\nThe attack is characterized as 'Easily exploitable' (AC:L) because it requires no specialized conditions, complex configuration, or user interaction (UI:N). The use of HTTPS for the attack allows the malicious traffic to potentially bypass simple network-level inspection if decryption or protocol-specific validation is not strictly enforced.\nThe scope of the impact is localized to the Oracle Data Integrator instance (S:U), yet the severity is categorized as critical (CVSS 9.8) due to the absolute control an attacker gains over the application once the execution flow is successfully redirected via the vulnerable REST interface."
}