CVE-2026-60999: Critical severity Oracle Oracle Data Integrator vulnerability
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60999?
CVE-2026-60999 has a critical severity rating of 9.8.
How do I fix CVE-2026-60999?
To mitigate CVE-2026-60999, upgrade to Oracle Data Integrator version 14.1.2.0.0 or later.
What is the impact of CVE-2026-60999?
The impact of CVE-2026-60999 allows for full data compromise through unauthenticated network access.
Is CVE-2026-60999 easy to exploit?
Yes, CVE-2026-60999 is classified as easily exploitable due to its network access characteristics.
What component of Oracle is affected by CVE-2026-60999?
CVE-2026-60999 specifically affects the Rest Service component of Oracle Data Integrator.