Description
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated network attacker can send specially crafted HTTP requests to the management interface of Oracle Identity Manager Connector, allowing full takeover of the component. The vulnerability permits an attacker to execute arbitrary code, modify configuration, and access or alter sensitive identity data, leading to total loss of confidentiality, integrity, and availability.

Affected Systems

Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0, components of Oracle Fusion Middleware used in PeopleSoft applications, are impacted.

Risk and Exploitability

The CVSS 3.1 score of 9.8 marks this flaw as critical, and its exploitability is low effort because it does not require authentication or authorized credentials; an attacker only needs network access to the connector’s HTTP interface. The EPSS score of less than 1% indicates that active exploitation is currently rare, and the flaw is not listed in the CISA KEV catalog, but the combination of a high CVSS score and unrestricted access points to a high practical risk for exposed systems.

Generated by OpenCVE AI on August 2, 2026 at 22:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Consult Oracle's July 2026 security alert for official remediation details and apply any available patch or update.
  • Restrict inbound HTTP traffic to the Identity Manager Connector to trusted networks or VPN, ensuring no unauthenticated access from public or untrusted networks.
  • Disable the management interface on public networks or enforce authentication for administrative endpoints.

Generated by OpenCVE AI on August 2, 2026 at 22:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Interface Exploitation Allows Full Takeover

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via HTTP in Oracle Identity Manager Connector

Sun, 26 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via HTTP in Oracle Identity Manager Connector

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager Connector
CPEs cpe:2.3:a:oracle:identity_manager_connector:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager_connector:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager Connector
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T18:06:19.060Z

Reserved: 2026-07-08T15:51:40.543Z

Link: CVE-2026-60535

cve-icon Vulnrichment

Updated: 2026-07-24T18:05:39.287Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function