Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Identity Manager product, specifically the legacy UI component, contains a flaw that an unauthenticated attacker can exploit over HTTP. Successful exploitation permits the attacker to take full control of the OIM instance, compromising confidentiality, integrity, and availability. The vulnerability is classified as a high‑severity remote code execution / authentication bypass flaw (CWE‑94 and CWE‑287).

Affected Systems

Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 are impacted. These versions appear in the CPE list and are the only ones noted in the CNA report. No other releases are mentioned.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity. The EPSS score is not available, so the precise exploitation probability is unknown, but the flaw is described as easily exploitable by an unauthenticated network attacker via HTTP. The vulnerability is not listed in CISA’s KEV catalog. Attackers need only HTTP access to an OIM instance; no prior authentication is required.

Generated by OpenCVE AI on August 18, 2026 at 22:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Identity Manager security patch that addresses CVE‑2026‑60727, as issued by Oracle.
  • Restrict HTTP connectivity to the OIM environment by firewall or VPN, allowing access only from trusted IP ranges.
  • Disable or remove the legacy UI component if it is not required, and enforce modern authentication mechanisms.

Generated by OpenCVE AI on August 18, 2026 at 22:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Identity Manager OIM Legacy UI
Weaknesses CWE-287
CWE-94

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:02.067Z

Reserved: 2026-07-08T15:51:55.583Z

Link: CVE-2026-60727

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:40.627

Modified: 2026-08-18T21:16:40.627

Link: CVE-2026-60727

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:00:14Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')