ZeroHour

CVE-2026-83232

moderate

Unauthenticated Takeover Flaw in Oracle Data Integrator Console (CVE-2026-83232)

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

Oracle Data Integrator, a component of Oracle Fusion Middleware, contains an easily exploitable flaw in the Console / Repository Explorer component that allows an unauthenticated attacker with network access over HTTP to fully compromise the product. Successful exploitation results in complete takeover of Oracle Data Integrator, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 9.8). The flaw affects supported versions 12.2.1.4.0 and 14.1.2.0.0, meaning organizations running current releases on those branches are exposed. Any instance whose Console or Repository Explorer is reachable by an attacker — particularly if internet-exposed — is at risk. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the CVE is not on the CISA KEV list, though the unauthenticated, network-exploitable nature makes it a high-priority patch target.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83232 if you run Oracle Data Integrator 12.2.1.4.0 or 14.1.2.0.0. Until patched, restrict network access to the ODI Console and Repository Explorer (allow-list trusted hosts, require VPN/authentication at a reverse proxy) and verify these endpoints are not exposed to the internet. Review Console and Repository Explorer access logs for unexplained or unauthenticated activity as an indicator of attempted exploitation.

Affected
Oracle Data Integrator (Oracle Fusion Middleware)12.2.1.4.0, 14.1.2.0.0
Estimated exposure
moderateLikely hundreds to a few thousand internet-reachable ODI consoles, plus an unknown but larger number of internally deployed enterprise instances — Oracle Data Integrator is enterprise data-integration middleware licensed by thousands of organizations, but its Console is typically deployed on internal networks, so the internet-exposed subset visible to public scans is expected to be…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Console / Repository Explorer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.