Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Identity Manager includes a flaw in its legacy web interface that permits an unauthenticated attacker to gain control of the system. The vulnerability enables an attacker with network access via HTTP to execute commands and compromise the integrity, confidentiality, and availability of the entire Identity Manager deployment. The CVSS base score of 9.8 reflects the potential for complete takeover without prior authentication or additional privileges.

Affected Systems

The flaw affects Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 as part of Oracle Fusion Middleware. Systems running these products expose the Legacy UI endpoint over HTTP, thereby providing the attack vector for the exploit.

Risk and Exploitability

Given the high CVSS score, the vulnerability is a critical risk when the Legacy UI is reachable over the network. The EPSS score is not available, but the absence of a KEV listing does not diminish the severity. Successful exploitation requires only network connectivity to the Legacy UI and yields full compromise of the Oracle Identity Manager instance, potentially affecting all users and data managed by the system.

Generated by OpenCVE AI on August 18, 2026 at 22:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or newer release that addresses CVE-2026-60721 to all affected Oracle Identity Manager installations.
  • Restrict network access to the Legacy UI by configuring firewall rules or placing the service behind a protected intranet gateway.
  • Disable the Legacy UI feature if it is not required for business operations.

Generated by OpenCVE AI on August 18, 2026 at 22:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Compromise of Oracle Identity Manager Legacy UI
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:01.099Z

Reserved: 2026-07-08T15:51:55.582Z

Link: CVE-2026-60721

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:40.253

Modified: 2026-08-18T21:16:40.253

Link: CVE-2026-60721

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:00:14Z

Weaknesses