Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Identity Manager product, specifically the legacy UI component, contains a flaw that an unauthenticated attacker can exploit over HTTP. Successful exploitation permits the attacker to take full control of the OIM instance, compromising confidentiality, integrity, and availability. The vulnerability is classified as a high‑severity remote code execution / authentication bypass flaw (CWE‑284).

Affected Systems

Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 are impacted. These versions are indicated by the provided CPE entries and are the only ones noted in the CNA report. No other releases are mentioned.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity. The EPSS score is < 1%, indicating a very low exploitation probability, but the flaw is described as easily exploitable by an unauthenticated network attacker via HTTP. The vulnerability is not listed in CISA’s KEV catalog. Attackers need only HTTP access to an OIM instance; no prior authentication is required.

Generated by OpenCVE AI on August 21, 2026 at 17:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Identity Manager security patch that addresses CVE‑2026‑60727, as issued by Oracle.
  • Restrict HTTP connectivity to the OIM environment by firewall or VPN, allowing access only from trusted IP ranges.
  • Disable or remove the legacy UI component if it is not required, and enforce modern authentication mechanisms.

Generated by OpenCVE AI on August 21, 2026 at 17:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Identity Manager Legacy UI

Fri, 21 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Identity Manager OIM Legacy UI
Weaknesses CWE-287
CWE-94

Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 18 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Identity Manager OIM Legacy UI
Weaknesses CWE-287
CWE-94

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T17:46:52.883Z

Reserved: 2026-07-08T15:51:55.583Z

Link: CVE-2026-60727

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:40.627

Modified: 2026-08-20T15:18:17.103

Link: CVE-2026-60727

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:00:03Z

Weaknesses