PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47056 Oracle CVE debrief

A critical vulnerability was discovered in Oracle Data Integrator, specifically in the Rest Service component. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. It allows unauthenticated attackers with network access via HTTP to compromise Oracle Data Integrator, potentially impacting additional products. Successful attacks can result in a complete takeover of Oracle Data Integrator. The vulnerability has a CVSS score of 10.0, indicating the highest severity, with impacts on Confidentiality, Integrity, and Availability. The source confidence is limited, and defenders should review the context and verify the affected scope.

Vendor
Oracle
Product
Data Integrator
CVSS
CRITICAL 10
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-27
Advisory published
2026-07-21
Advisory updated
2026-07-27

Who should care

Organizations using Oracle Data Integrator versions 12.2.1.4.0 and 14.1.2.0.0 should prioritize patching this vulnerability. The CVSS score of 10.0 indicates the highest severity, with impacts on Confidentiality, Integrity, and Availability. Operators, platform administrators, vulnerability management teams, and security teams should review the context and verify the affected scope.

Technical summary

The vulnerability in Oracle Data Integrator's Rest Service component can be exploited by unauthenticated attackers with network access via HTTP. The CVSS Vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, indicating a critical vulnerability with high impacts on Confidentiality, Integrity, and Availability. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle Data Integrator. The technical impact is significant, and defenders should prioritize patching.

Defensive priority

Highest Priority: Critical vulnerability with highest severity and significant technical impact. Immediate patching is recommended, and compensating controls should be implemented while remediation is scheduled and verified. Monitoring and detection should be reviewed for exposed assets that need extra review. Exceptions should be tracked, and remediated assets should be retested before closing the item.

Recommended defensive actions

  • Apply patches or updates provided by Oracle to address the vulnerability in Oracle Data Integrator.
  • Implement compensating controls, such as restricting network access to Oracle Data Integrator.
  • Monitor Oracle Data Integrator systems for suspicious activity.
  • Inventory and verify the versions of Oracle Data Integrator in use.
  • Consider implementing additional security measures, such as multi-factor authentication.

Evidence notes

The CVE record was published on 2026-07-21T22:17:11.370Z and was last modified on 2026-07-27T20:10:54.243Z. The NVD entry is currently Analyzed. The vulnerability has a CVSS score of 10.0, indicating the highest severity. The evidence is limited, and defenders should verify the affected scope and vendor guidance. The CVE details are based on the NVD entry and the official CVE record.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:11.370Z and has not been modified since then. The NVD entry is currently Analyzed.