Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A flaw within the Core component of Oracle Identity Manager allows an attacker who possesses only low-level privileges and network access on the T3 or IIOP protocols to compromise the system. Exploitation of this vulnerability can lead to full system takeover, providing the attacker with complete control. The weakness results in confidentiality, integrity, and availability damage with a CVSS 3.1 base score of 8.8, indicating high severity.

Affected Systems

Oracle Corporation's Identity Manager product, specifically versions 12.2.1.4.0 and 14.1.2.1.0, is affected. These are part of the Oracle Fusion Middleware suite and rely on the Core component for identity management.

Risk and Exploitability

The CVSS score reflects critical impact across all dimensions, but the EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to be able to reach the system over the network and use the T3 or IIOP ports, indicating a remote network‑based attack vector that is easily exploitable by users with low privileges. These characteristics raise the risk to organizations relying on OIM for identity and access control.

Generated by OpenCVE AI on September 17, 2026 at 06:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a supported release that addresses the identified flaw.
  • Restrict network exposure of the T3 and IIOP interfaces to trusted hosts and enforce strict firewall rules.
  • Enable comprehensive logging and regularly review authentication and access logs for anomalous activity.

Generated by OpenCVE AI on September 17, 2026 at 06:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Code Execution via T3/IIOP in Oracle Identity Manager

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:30:53.951Z

Reserved: 2026-08-04T22:06:34.605Z

Link: CVE-2026-70915

cve-icon Vulnrichment

Updated: 2026-09-16T14:53:46.407Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:42.110

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-70915

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T06:15:04Z

Weaknesses