A critical remote code execution vulnerability (CVE-2026-47056) has been disclosed in Oracle Data Integrator, a component of Oracle Fusion Middleware. The flaw resides in the Rest Service module and affects versions 12.2.1.4.0 and 14.1.2.0.0. Attackers can exploit this vulnerability without authentication by leveraging HTTP-based network access, potentially leading to full system compromise. The vulnerability’s CVSS 3.1 score of 10.0 reflects its ease of exploitation and severe impact on confidentiality, integrity, and availability. Notably, while the vulnerability originates in Oracle Data Integrator, successful exploitation could cascade to affect other interconnected systems (scope change). Organizations operating affected versions are strongly advised to apply vendor-released patches immediately. In the absence of patches, network-level mitigations such as restricting HTTP access to trusted sources should be implemented. Continuous monitoring for anomalous HTTP traffic patterns is recommended to detect potential exploitation attempts. This vulnerability underscores the importance of timely updates for enterprise middleware platforms exposed to external networks.
CRITICAL
CVSS 10.0
CVE-2026-47056
2026-08-13
Critical Remote Code Execution Vulnerability in Oracle Data Integrator (CVE-2026-47056)
A critical vulnerability in Oracle Data Integrator allows unauthenticated attackers to take control of affected systems via HTTP. Oracle Fusion Middleware versions 12.2.1.4.0 and 14.1.2.0.0 are impacted. Immediate patching is required to mitigate this high-severity risk.