Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

The Oracle Identity Manager Legacy UI component suffers from an authentication and access control flaw (CWE‑284) that lets a low‑privileged attacker with network access via HTTP gain authorization and fully compromise the instance, giving the attacker control over confidentiality, integrity, and availability of the OIM service. The flaw is easily exploitable and results in a complete takeover of the Oracle Identity Manager deployment.

Affected Systems

Affected products are Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0, both part of Oracle Fusion Middleware. The vulnerability does not extend beyond the Legacy UI component of these versions.

Risk and Exploitability

The CVSS v3.1 base score of 8.8 signals high severity, while the EPSS score of less than 1% indicates a low current probability of exploitation. The flaw is not listed in the CISA KEV catalog; however, because it allows full system compromise, organizations are strongly encouraged to remediate. The likely attack vector is a simple HTTP request from a low‑privileged attacker who can reach the OIM instance, with no special privileges required beyond network connectivity.

Generated by OpenCVE AI on September 20, 2026 at 12:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available Oracle patch or upgrade that addresses the authentication and access‑control flaw, if such a patch is released; staying up‑to‑date is critical.
  • Restrict HTTP access to the Oracle Identity Manager instance using firewalls or access‑control lists so that only trusted networks or IP ranges can reach the OIM services, thereby reducing exposure to low‑privileged attackers.
  • Enable comprehensive logging of all authentication attempts and privileged actions in Oracle Identity Manager, and actively monitor these logs for anomalous activity, responding promptly to suspicious events.

Generated by OpenCVE AI on September 20, 2026 at 12:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Oracle OIM Legacy UI Authentication Bypass Enables Full Takeover

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:30:25.715Z

Reserved: 2026-08-13T18:41:45.892Z

Link: CVE-2026-73942

cve-icon Vulnrichment

Updated: 2026-09-16T14:53:56.482Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:17:45.160

Modified: 2026-09-22T19:51:27.643

Link: CVE-2026-73942

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T12:15:17Z

Weaknesses