Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-60999: Oracle Data Integrator 14.1.2.0.0 Rest Service Takeover Risk
CVE-2026-60999 · published 2 months ago
Summary
If an attacker can access your Oracle Data Integrator system over the internet, they may be able to take control of it. This is a serious risk because it could allow them to access sensitive information, disrupt your business, or even delete data. You should update to a fixed version of Oracle Data Integrator as soon as possible to protect your system.
Original advisory text
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability a...
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
CWE-306Missing Authentication for Critical Function
Timeline
Published21 Jul 2026
Updated27 Sep 2026
First seen24 Jul 2026
Sources
CVE-2026-60999 · NVD
Track software like this
Free during beta