Description
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker who has access to the physical network segment where the Oracle Identity Manager Connector runs to compromise the component. Successful exploitation can lead to complete takeover, giving the attacker full control over the connector, potentially exposing sensitive identity data and enabling further lateral movement within the organization. The flaw carries a high severity risk with a CVSS 3.1 score of 7.5, indicating significant confidentiality, integrity, and availability impacts.

Affected Systems

The Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0 are affected. These versions are part of Oracle Fusion Middleware and provide connectivity between identity management systems and various back‑end resources. Operators running either of these releases should immediately verify their deployment and plan for the application of the vendor‑issued fix.

Risk and Exploitability

The potential for exploitation requires only local physical access and no authentication, as the attack vector requires the attacker to be on the same physical network segment where the connector runs. The CVSS vector (AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) confirms that the flaw is remotely exploitable on the adjacent network and leads to complete compromise. The EPSS score is < 1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog at this time. The high CVSS base score of 7.5 and the potential for complete takeover warrant prompt remediation.

Generated by OpenCVE AI on August 21, 2026 at 13:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Limit physical access to the network segment where Oracle Identity Manager Connector operates
  • Deploy network segmentation and firewall rules to restrict connectivity to the connector to only trusted subnets
  • Monitor the connector for anomalous activity and regularly review audit logs for signs of compromise
  • Verify vendor website for the latest security advisories and apply any future updates that address CVE-2026-60993

Generated by OpenCVE AI on August 21, 2026 at 13:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Physical Access Exploit Allows Takeover of Oracle Identity Manager Connector
Weaknesses CWE-284

Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager Connector
CPEs cpe:2.3:a:oracle:identity_manager_connector:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager_connector:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager Connector
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T13:58:25.819Z

Reserved: 2026-07-08T15:51:55.606Z

Link: CVE-2026-60993

cve-icon Vulnrichment

Updated: 2026-08-21T13:58:18.241Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:16:50.910

Modified: 2026-08-21T14:16:51.590

Link: CVE-2026-60993

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T14:00:13Z

Weaknesses