SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60999 2026-07-21

Oracle Data Integrator Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60999)

"A critical vulnerability in Oracle Data Integrator's REST Service component lets an unauthenticated attacker fully compromise the product over the network, earning a CVSS 3.1 base score of 9.8."

A critical vulnerability in Oracle Data Integrator's REST Service component lets an unauthenticated attacker fully compromise the product over the network, earning a CVSS 3.1 base score of 9.8.

What Is It

CVE-2026-60999 is a vulnerability in the REST Service component of Oracle Data Integrator, part of Oracle Fusion Middleware. According to Oracle's NVD record, it is an "easily exploitable" flaw that allows an unauthenticated attacker with network access via HTTPS to compromise Oracle Data Integrator. Successful exploitation can result in complete takeover of the product.

Why It Matters

The flaw carries a CVSS 3.1 base score of 9.8 (CRITICAL), with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That combination, network attack vector, low complexity, no privileges, and no user interaction required, means an attacker needs only network reachability to the service. The impact is maximal across all three axes: high confidentiality, integrity, and availability impact. Because Oracle Data Integrator handles data movement and transformation across enterprise systems, a full takeover could expose or alter sensitive data pipelines.

There is no CISA KEV entry in the supplied material, so active exploitation is not confirmed by KEV at this time.

What's Vulnerable

Patch Status

The vulnerability was published on 2026-07-21 and is credited to Oracle's security alert channel. Oracle's referenced advisory is the Critical Patch Update for July 2026 (cpujul2026.html), which is the source for remediation details. Administrators running the affected version should consult that Oracle Critical Patch Update and apply the fixes it provides. No separate CISA-mandated remediation action is present in the supplied data.

Sources