CVE-2026-47056
Analyzed Analyzed - Analysis Complete

Oracle Data Integrator Remote Code Execution

Vulnerability report for CVE-2026-47056, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-27

Assigner: Oracle

Description

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator. While the vulnerability is in Oracle Data Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-27
Generated
2026-08-11
AI Q&A
2026-07-22
EPSS Evaluated
2026-08-09
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
oracle data_integrator 12.2.1.4.0
oracle data_integrator 14.1.2.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a critical vulnerability in Oracle Data Integrator, a data integration tool. It allows unauthenticated attackers to remotely take over the system via HTTP network access. The flaw affects versions 12.2.1.4.0 and 14.1.2.0.0 and has a maximum severity score of 10.0 due to its impact on confidentiality, integrity, and availability.

Detection Guidance

This vulnerability affects Oracle Data Integrator versions 12.2.1.4.0 and 14.1.2.0.0. Detection involves checking for exposed Oracle Data Integrator REST services on your network. Use network scanning tools like nmap to identify open ports (default Oracle ports are 7001, 7002, 9001, etc.). Inspect HTTP responses for Oracle Data Integrator endpoints. Monitor logs for unusual access patterns or unauthenticated requests to /odi/ or /rest/ paths.

Impact Analysis

An attacker could exploit this to completely take over your Oracle Data Integrator instance. This could lead to unauthorized data access, modification, or deletion, and potentially affect other connected systems. The high CVSS score indicates widespread potential impact.

Compliance Impact

This vulnerability could severely impact compliance with GDPR and HIPAA. Unauthorized access could lead to data breaches, violating confidentiality requirements. The integrity and availability impacts may also breach regulatory standards for data protection and system reliability.

Mitigation Strategies

Apply the latest Oracle Data Integrator patches immediately as they become available. Disable HTTP access to the Rest Service component if not required. Restrict network access to the Oracle Data Integrator system using firewalls or network segmentation. Monitor Oracle's security advisories for updates and apply them promptly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47056. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart