Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Identity Manager’s Legacy UI component contains a flaw that a user with low privileges can exploit when connected to the service over the T3 or IIOP protocols. An attacker can use this vulnerability to bypass normal authentication checks and gain full control of the system. The success of the attack would give the attacker the ability to read sensitive data, modify or delete configuration, and ultimately take over the entire Identity Manager installation. The security impact is severe, affecting confidentiality, integrity, and availability of the service.

Affected Systems

The affected entity is Oracle Corporation’s Oracle Identity Manager. Versions 12.2.1.4.0 and 14.1.2.1.0 are listed as vulnerable. The Legacy UI component of these releases is the attack surface.

Risk and Exploitability

The CVSS v3.1 base score is 8.8, reflecting a high severity risk. The EPSS score of 0.00432 indicates an extremely low probability of exploitation, yet the high base score indicates that when it is exploited, the impact is severe. The vulnerability is not yet listed in the CISA KEV catalog, so there are no known deployments exploited in the wild. Attackers can reach the vulnerable service from any host with network access to the T3 or IIOP port, and the low privileged requirement means no elevated rights are needed; no user interaction is required beyond establishing a network connection.

Generated by OpenCVE AI on August 21, 2026 at 16:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch which resolves the flaw or upgrade to a version that contains the fix.
  • Limit network exposure of the T3 and IIOP ports by enabling firewall filtering or moving the service to a trusted subnet so that only authorized hosts can communicate with Oracle Identity Manager.
  • Enforce strict role‑based access controls within Oracle Identity Manager to restrict administrative actions and prevent unauthorized use of privileged functions.

Generated by OpenCVE AI on August 21, 2026 at 16:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Exploit Enables Complete Takeover of Oracle Identity Manager

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T17:38:09.587Z

Reserved: 2026-07-08T15:51:55.582Z

Link: CVE-2026-60716

cve-icon Vulnrichment

Updated: 2026-08-20T17:37:35.467Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:16:40.017

Modified: 2026-08-20T18:16:31.883

Link: CVE-2026-60716

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T16:15:03Z

Weaknesses