Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Installer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Identity Manager executes to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Identity Manager Installer component contains insufficient access controls that enable a local user with minimal privileges to execute installer code. Exploitation grants the attacker full control of the Identity Manager instance, affecting confidentiality, integrity, and availability. The vulnerability is a broken access control flaw that allows a local low‑privileged attacker to override system security.

Affected Systems

Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 from Oracle Corporation are affected. The flaw resides in the installer service that runs on the Identity Manager server.

Risk and Exploitability

The CVSS v3.1 base score of 7.8 indicates high severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation. Attackers only need local access with low privileges; no network connectivity is required. The flaw is not listed in the CISA KEV catalog, but within a compromised environment the risk remains substantial because a local attacker can gain full control of the Identity Manager instance.

Generated by OpenCVE AI on August 21, 2026 at 02:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Identity Manager patch that addresses the Installer vulnerability as detailed in Oracle’s August 2026 security alert.
  • Disable the installer service on production servers or restrict its execution rights to a tightly controlled administrative group.
  • Remove or disable any unnecessary local user accounts that could be exploited to run the installer.
  • Monitor installer execution logs for suspicious activity and enforce strict auditing.

Generated by OpenCVE AI on August 21, 2026 at 02:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Identity Manager Installer Component

Thu, 20 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Identity Manager Installer

Thu, 20 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Identity Manager Installer
Weaknesses CWE-285

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Thu, 20 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Wed, 19 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Oracle Identity Manager Installer Vulnerability Enables Local Account Compromise
Weaknesses CWE-284
CWE-285

Wed, 19 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Title Oracle Identity Manager Installer Vulnerability Enables Local Account Compromise
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Installer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Identity Manager executes to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T17:59:34.551Z

Reserved: 2026-08-04T22:06:34.618Z

Link: CVE-2026-71111

cve-icon Vulnrichment

Updated: 2026-08-20T17:51:31.799Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:11.627

Modified: 2026-08-20T18:16:43.733

Link: CVE-2026-71111

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T02:45:04Z

Weaknesses