Description
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Microsoft Active Directory). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Identity Manager Connector is vulnerable to a remote LDAP-based privilege escalation that can lead to complete takeover of the connector. The flaw resides in the Microsoft Active Directory component of the connector and allows an attacker with high privileges and network access to LDAP traffic to bypass the connector's authentication controls. Successful exploitation would compromise the confidentiality, integrity, and availability of the connector, potentially exposing sensitive identity data and disrupting access for legitimate users.

Affected Systems

Affected vendors: Oracle Corporation; product: Oracle Identity Manager Connector. Versions 12.2.1.4.0 and 14.1.2.1.0 are listed as vulnerable. These versions are part of the Oracle Fusion Middleware suite and target the Microsoft Active Directory integration component.

Risk and Exploitability

The CVSS 3.1 base score is 8.0, indicating high severity. The attack vector, requiring network access (AV:N) and high privilege (PR:H), and a scope change (S:C) suggests that exploitation could affect multiple systems within an environment. Although the EPSS score is < 1%, the entry is not listed in the CISA KEV catalog, the presence of a scope change and the need for high‑privilege LDAP actions imply a realistic risk of broader compromise. The likely attack path involves an attacker issuing carefully crafted LDAP queries to the connector and leveraging the flaw to gain administrative control, potentially taking over the entire service.

Generated by OpenCVE AI on August 21, 2026 at 13:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Consult Oracle’s security advisories for any available patches or updates, applying any identified fix as soon as it becomes available.
  • Implement network segmentation or firewall rules to limit inbound LDAP traffic to the connector to a trusted subset of hosts, reducing the attack surface for LDAP-based exploitation.
  • Enable comprehensive logging of LDAP authentication attempts and connector activity, and monitor for anomalous patterns that could indicate a takeover or privilege escalation attempt.

Generated by OpenCVE AI on August 21, 2026 at 13:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title High Privilege LDAP Exploit Enables Takeover of Oracle Identity Manager Connector
Weaknesses CWE-284

Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Microsoft Active Directory). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager Connector
CPEs cpe:2.3:a:oracle:identity_manager_connector:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager_connector:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager Connector
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T14:52:24.671Z

Reserved: 2026-07-08T15:51:55.607Z

Link: CVE-2026-60998

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:16:51.400

Modified: 2026-08-21T15:16:44.490

Link: CVE-2026-60998

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:30:04Z

Weaknesses