Description
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Connectors and Connector Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An Oracle Identity Manager Connector vulnerability enables a high‑privileged attacker with network access over HTTPS to acquire control of the connector, allowing the attacker to create, delete, or modify critical data. The flaw impacts both confidentiality and integrity of all data accessible through the connector. The product controls sensitive identity information, so unauthorized changes could lead to data tampering or loss of trust in the system.

Affected Systems

Oracle Identity Manager Connector of Oracle Fusion Middleware, specifically versions 12.2.1.4.0 and 14.1.2.1.0, are known to be affected. These versions are part of the Oracle Fusion Middleware suite, which supports various enterprise identity and access management components.

Risk and Exploitability

The CVSS 3.1 score of 8.7 indicates a high‑severity flaw that grants full control over connector data. Because the attack requires network access via HTTPS and a high‑privileged user context, the exploitation vector is likely remote but may need privileged or a compromised account. The EPSS score is < 1%, but the lack of listing in the CISA KEV catalog does not mitigate the risk; the vulnerability remains exploitable and can produce significant impact if the connector is exposed to untrusted networks.

Generated by OpenCVE AI on August 21, 2026 at 15:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Identity Manager Connector that addresses CVE‑2026‑60996
  • If a patch is not yet available, restrict HTTPS access to the connector from trusted IP ranges only
  • Review and enforce the least‑privilege principle for accounts that can interact with the connector

Generated by OpenCVE AI on August 21, 2026 at 15:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title High‑Privilege Remote Access via HTTPS to Oracle Identity Manager Connector

Fri, 21 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title High Privilege Exploit via HTTPS in Oracle Identity Manager Connector
Weaknesses CWE-284

Wed, 19 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title High Privilege Exploit via HTTPS in Oracle Identity Manager Connector
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Connectors and Connector Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle identity Manager Connector
CPEs cpe:2.3:a:oracle:identity_manager_connector:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager_connector:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager Connector
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Identity Manager Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T13:49:40.564Z

Reserved: 2026-07-08T15:51:55.606Z

Link: CVE-2026-60996

cve-icon Vulnrichment

Updated: 2026-08-21T13:48:07.113Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:51.277

Modified: 2026-08-26T17:35:09.720

Link: CVE-2026-60996

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T16:00:15Z

Weaknesses