Description
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Identity Manager Connector product contains a local privilege escalation flaw that allows a low‑privileged user who can log on to the infrastructure hosting the connector to compromise the service. Successful exploitation results in full takeover of the connector, with confidentiality, integrity, and availability all impacted as described by the CVSS vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The vulnerability is deemed easily exploitable due to its low attack complexity and the minimal prerequisites of local logon and low privilege. It represents a high‑severity flaw capable of delivering complete control over the identity management infrastructure.

Affected Systems

Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0 are affected. These versions run within Oracle Fusion Middleware and target the core component of the connector. The flaw does not affect higher or older releases beyond those specified.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity rating. The EPSS score is <1% which indicates a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local with no user interaction required, making it a concern primarily for users with low‑level local accounts or compromised credentials. Because the flaw allows a total takeover of the connector, the risk to confidentiality, integrity, and availability is significant for any environment relying on the affected versions.

Generated by OpenCVE AI on August 21, 2026 at 13:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle security update that fixes the privilege escalation flaw for Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0.
  • Restrict local account privileges that can run the Connector services, ensuring only trusted administrators have logon rights.
  • Configure the operating system to block or monitor local execution of Connector binaries, applying necessary file‑system permissions to prevent unauthorized use.
  • Consistently monitor Connector logs and system audit logs for anomalous activity that may indicate exploitation attempts.

Generated by OpenCVE AI on August 21, 2026 at 13:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Identity Manager Connector Accessible to Low‑Privileged Users
Weaknesses CWE-284

Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager Connector
CPEs cpe:2.3:a:oracle:identity_manager_connector:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager_connector:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager Connector
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T14:01:14.762Z

Reserved: 2026-07-08T15:51:55.606Z

Link: CVE-2026-60991

cve-icon Vulnrichment

Updated: 2026-08-21T14:01:08.644Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:16:50.683

Modified: 2026-08-21T14:16:51.337

Link: CVE-2026-60991

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T14:00:13Z

Weaknesses