SYS::ONLINE
Wasteland.
Briefs1406
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-47056 2026-07-21

CVE-2026-47056: Critical Unauthenticated Takeover in Oracle Data Integrator

"A maximum-severity flaw in Oracle Data Integrator's REST Service lets an unauthenticated attacker fully compromise the product over HTTP, with impact spilling into adjacent systems."

A maximum-severity flaw in Oracle Data Integrator's REST Service lets an unauthenticated attacker fully compromise the product over HTTP, with impact spilling into adjacent systems.

What Is It

CVE-2026-47056 is a critical vulnerability in the REST Service component of Oracle Data Integrator, part of Oracle Fusion Middleware. It carries a CVSS 3.1 base score of 10.0 (CRITICAL) with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. The flaw is easily exploitable: an unauthenticated attacker with network access via HTTP can compromise Oracle Data Integrator, resulting in full takeover of the product. Because the scope is changed, successful attacks may significantly impact additional products beyond Data Integrator itself.

Why It Matters

This is a perfect 10.0 score; the highest possible. It requires no privileges, no user interaction, and low attack complexity, meaning exploitation is straightforward for any attacker who can reach the service over the network. The confidentiality, integrity, and availability impacts are all rated HIGH, and the scope change means blast radius extends to other connected products. Oracle Data Integrator is a data integration platform that frequently touches sensitive enterprise data pipelines, making a takeover especially consequential.

What's Vulnerable

The affected product is Oracle Data Integrator (Oracle Fusion Middleware), specifically the REST Service component. The supported versions confirmed affected are:

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running the affected versions should apply the fixes referenced in the Oracle Critical Patch Update Advisory. This CVE does not appear in the supplied CISA KEV data, so there is no confirmed record of active exploitation in the provided sources.

Sources