Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60723

CVE-2026-60723: Oracle Data Integrator Privilege Escalation

CVE-2026-60723 is a privilege escalation vulnerability in Oracle Data Integrator affecting versions 12.2.1.4.0 and 14.1.2.0.0. This flaw allows unauthorized data access and modification. This article covers technical details, affected versions, impact, and mitigation strategies.

Published:

CVE-2026-60723 Overview

CVE-2026-60723 is a high-severity vulnerability in the Oracle Data Integrator (ODI) product of Oracle Fusion Middleware. The flaw resides in the Market Place component and affects supported versions 12.2.1.4.0 and 14.1.2.0.0. A low-privileged attacker with logon access to the infrastructure where Oracle Data Integrator executes can compromise the product. The vulnerability has a scope change, meaning successful exploitation may impact additional products beyond ODI itself. Attackers can gain unauthorized creation, deletion, or modification access to critical data, along with complete read access to all ODI-accessible data.

Critical Impact

Local, low-privileged attackers can achieve full read and write access to critical Oracle Data Integrator data, with impact extending beyond ODI due to the scope change.

Affected Products

  • Oracle Data Integrator 12.2.1.4.0
  • Oracle Data Integrator 14.1.2.0.0
  • Oracle Fusion Middleware (Market Place component)

Discovery Timeline

Technical Details for CVE-2026-60723

Vulnerability Analysis

The vulnerability affects the Market Place component of Oracle Data Integrator, part of the Oracle Fusion Middleware stack. Oracle Data Integrator is an extract-transform-load (ETL) platform used to move and transform data across enterprise systems. The Market Place component allows extensions and integrations to be added to the ODI environment.

Exploitation requires local access to the infrastructure running ODI and only low-level privileges. No user interaction is required. Because the vulnerability produces a scope change, an attacker who compromises ODI can affect components and data managed by other products relying on the same infrastructure.

Successful exploitation yields full confidentiality and integrity impact. Attackers can create, delete, or modify any data accessible to ODI and read all ODI-accessible data. Availability is not affected. The EPSS probability is 0.16%, reflecting a low observed likelihood of exploitation in the wild at publication time.

Root Cause

Oracle has not published root cause specifics for this issue. Based on Oracle's advisory language, the flaw exists in how the Market Place component handles operations available to authenticated users on the ODI host, permitting them to affect data and resources outside their intended authorization boundary.

Attack Vector

The attack vector is local. An attacker must first hold a valid low-privileged account with logon access to the server hosting Oracle Data Integrator. From that foothold, the attacker interacts with the Market Place component to escalate access over ODI data and cross the trust boundary into other products in the environment. No end-user interaction is required to complete the attack.

No public proof-of-concept exploit code is available, and no verified code samples have been released by Oracle. Refer to the Oracle Security Alert - July 2026 for vendor-supplied technical details.

Detection Methods for CVE-2026-60723

Indicators of Compromise

  • Unexpected logon sessions on ODI hosts from local or service accounts with no operational reason to access the system.
  • Unusual read, create, modify, or delete activity against ODI repositories, work schemas, or connected data stores.
  • Invocation of Market Place component functions by accounts that historically never used them.
  • New or modified artifacts appearing in ODI projects, mappings, or scenarios without a matching change ticket.

Detection Strategies

  • Correlate operating system authentication logs on ODI hosts with ODI application audit logs to identify low-privileged accounts performing sensitive Market Place actions.
  • Baseline normal Market Place component usage and alert on deviations, including off-hours activity or activity from non-administrative accounts.
  • Monitor for scope-change signals such as ODI-linked service accounts accessing resources owned by other Fusion Middleware products.

Monitoring Recommendations

  • Forward ODI audit logs, Fusion Middleware logs, and host authentication logs to a centralized logging platform for correlation.
  • Enable database auditing on ODI master and work repositories to capture unauthorized schema and data modifications.
  • Review privileged group membership and local logon rights on ODI servers weekly and alert on additions.

How to Mitigate CVE-2026-60723

Immediate Actions Required

  • Apply the July 2026 Oracle Critical Patch Update to all Oracle Data Integrator 12.2.1.4.0 and 14.1.2.0.0 deployments as the primary remediation.
  • Inventory all ODI installations, including non-production environments, and confirm patch coverage across each host.
  • Restrict interactive and remote logon rights on ODI servers to a minimal set of administrators.
  • Rotate credentials for accounts with logon access to ODI infrastructure following patching.

Patch Information

Oracle addressed CVE-2026-60723 in the July 2026 Critical Patch Update. Administrators should download and install the fixes referenced in the Oracle Security Alert - July 2026 advisory. Both supported affected versions, 12.2.1.4.0 and 14.1.2.0.0, are covered by the CPU. Oracle recommends applying CPU patches without delay because unpatched systems have been repeatedly targeted after prior CPU disclosures.

Workarounds

  • No official vendor workaround is listed; patching is the supported remediation.
  • Reduce the local logon footprint on ODI hosts by removing unnecessary user and service accounts.
  • Enforce host-based access controls and jump-server-only administrative paths to ODI systems until patches are applied.
  • Increase audit logging verbosity on the Market Place component and connected repositories to shorten detection time during the exposure window.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.