Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation to full system compromise
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Oracle Identity Manager allows an attacker with low privilege who can reach the application over HTTP to take over the system. The flaw facilitates full control, thereby compromising confidentiality, integrity, and availability. The weakness is an improper authorization flaw (CWE‑284).

Affected Systems

Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 are affected.

Risk and Exploitability

The CVSS Base Score of 8.8 indicates a high severity impact, while the EPSS score of less than 1% shows exploitation remains unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires only low privileged credentials and simple network access over HTTP, making it relatively easy to attempt in environments where the Identity Manager is exposed to the network.

Generated by OpenCVE AI on September 17, 2026 at 05:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Identity Manager patch or upgrade to an unaffected version.
  • Restrict HTTP access to the Identity Manager server to trusted hosts through firewall or network segmentation.
  • Enable multi‑factor authentication and enforce least‑privilege for all accounts that interact with the Identity Manager web interface.

Generated by OpenCVE AI on September 17, 2026 at 05:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Identity Manager via HTTP

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:30:48.653Z

Reserved: 2026-08-04T22:06:34.613Z

Link: CVE-2026-71047

cve-icon Vulnrichment

Updated: 2026-09-16T14:53:48.873Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:42.230

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-71047

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T05:45:18Z

Weaknesses