Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that the vulnerability stems from improper access control in the OIM Legacy UI component, allowing a low‑privileged attacker with network access to send crafted HTTP requests and achieve a full takeover of the Oracle Identity Manager system. This would compromise confidentiality, integrity, and availability. The CVSS 3.1 base score is 8.8, indicating a high severity risk to affected deployments.

Affected Systems

Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 are affected. The affected component is the Legacy UI of the Oracle Fusion Middleware OIM product.

Risk and Exploitability

Based on the description, the likely attack vector is network access via HTTP to the OIM Legacy UI component, where a low‑privileged attacker can send crafted requests exploiting improper access control, potentially gaining administrator‑level access and allowing full takeover of the system. The exploit requires only network connectivity and a low‑privileged credential, making it relatively easy to execute. The EPSS score is < 1%, indicating a low probability of exploitation in the wild, but the high CVSS score and absence from the KEV catalogue still suggest that when exploitation does occur, it carries significant risk.

Generated by OpenCVE AI on August 21, 2026 at 12:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Identity Manager security patch or upgrade to a fixed release for versions 12.2.1.4.0 and 14.1.2.1.0 as released by Oracle.
  • If the patch is not yet available, restrict HTTP access to the OIM Legacy UI by firewall rules or VPN to only trusted IP ranges.
  • Enable detailed logging of authentication attempts and regularly audit these logs for signs of unauthorized activity.

Generated by OpenCVE AI on August 21, 2026 at 12:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Vulnerability Enabling Full Compromise of Oracle Identity Manager
Weaknesses CWE-284

Thu, 20 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T16:28:18.159Z

Reserved: 2026-07-08T15:51:55.614Z

Link: CVE-2026-61118

cve-icon Vulnrichment

Updated: 2026-08-21T14:59:12.844Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:16:54.177

Modified: 2026-08-24T17:17:30.720

Link: CVE-2026-61118

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:15:05Z

Weaknesses