Description
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Studio). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Data Integrator Studio permits a low‑privileged attacker who can log into the underlying infrastructure to gain full control of the appliance. The flaw enables an attacker to compromise the application, resulting in loss of confidentiality, integrity, and availability of all data processed by the tool. The weakness is an example of improper access control or missing authorization.

Affected Systems

Oracle Data Integrator Studio versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability is present in the Studio component of Oracle Fusion Middleware.

Risk and Exploitability

The CVSS score of 7.8 indicates a high‑severity weakness, but the EPSS shows a very low exploitation probability (<1%). The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only local access—an attacker with ordinary user rights can trigger the flaw without any additional permissions or user interaction, making the pathway straightforward for anyone who can log into the system where Oracle Data Integrator runs.

Generated by OpenCVE AI on August 4, 2026 at 17:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a version of Oracle Data Integrator that has removed the vulnerability.
  • Restrict local logon rights for users who need to run Oracle Data Integrator, enforcing least privilege on the infrastructure.
  • Monitor the environment for unauthorized changes or unexpected activity in the Data Integrator service after applying the fix.

Generated by OpenCVE AI on August 4, 2026 at 17:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Local Access Enables Complete Control of Oracle Data Integrator Studio

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Access Enables Complete Control of Oracle Data Integrator Studio

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Data Integrator Studio
Weaknesses CWE-284
CWE-862

Thu, 23 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Data Integrator Studio
Weaknesses CWE-284
CWE-862

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Studio). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle data Integrator
CPEs cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:data_integrator:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle data Integrator
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Data Integrator
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T12:30:44.412Z

Reserved: 2026-07-08T15:51:40.548Z

Link: CVE-2026-60625

cve-icon Vulnrichment

Updated: 2026-07-27T12:30:40.609Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:15:02Z

Weaknesses
  • CWE-269

    Improper Privilege Management