Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Oracle Identity Manager legacy UI implements improper access control that allows an attacker with low privilege to use the public HTTP interface to gain full control of the identity management system. The vulnerability requires a low‑privileged attacker with network access via HTTP and results in complete compromise of confidentiality, integrity, and availability, enabling an attacker to read, modify, delete identity data and execute privileged operations. The weakness is classified as ‘CWE‑284: Improper Access Control’.

Affected Systems

Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 are affected. These releases are part of Oracle Fusion Middleware and expose a legacy UI component over standard HTTP endpoints. Vulnerable installations are those that allow unauthenticated or low‑privilege users to reach the legacy UI without additional network restriction.

Risk and Exploitability

The CVSS v3.1 base score of 8.8 indicates high severity. The attack vector is remote over the network (AV:N) with low effort (AC:L), low privilege (PR:L) and no user interaction (UI:N). The EPSS score is less than 1% and the CVE is not listed in CISA’s KEV catalog, but the low exploitation probability does not reduce the risk; exposed deployments are susceptible to remote takeover.

Generated by OpenCVE AI on August 21, 2026 at 16:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Monitor Oracle security alerts for patches or updates to Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0
  • Restrict network access to the legacy UI by configuring firewalls or VPNs to limit traffic to trusted networks
  • Disable or remove the legacy UI component if not required, and enforce strict authentication and session validation for any remaining interfaces

Generated by OpenCVE AI on August 21, 2026 at 16:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Identity Manager Leads to Remote Takeover

Tue, 18 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Identity Manager Leads to Remote Takeover
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T17:57:00.504Z

Reserved: 2026-07-08T15:51:55.581Z

Link: CVE-2026-60715

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:39.897

Modified: 2026-08-20T15:19:54.840

Link: CVE-2026-60715

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T16:15:03Z

Weaknesses