Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Identity Manager accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-09-15
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Patch
AI Analysis

Impact

Oracle Identity Manager’s Legacy UI contains an access control flaw that allows an attacker with high privileges, who can reach the system over HTTP, to gain unauthorized read or write access to critical data. This may allow complete compromise of all data accessible through Oracle Identity Manager and, depending on the environment, can potentially affect other products as the authority scope is changed.

Affected Systems

The flaw is present in Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0, specifically targeting the Legacy UI component. These versions are part of the Oracle Fusion Middleware suite and are used for identity, access, and user management within enterprise environments.

Risk and Exploitability

The CVSS base score of 7.6 indicates a high impact on confidentiality with low integrity damage. The EPSS score, listed as less than 1%, signals a very low current exploitation likelihood, and the vulnerability is not yet cataloged as a known exploited vulnerability. Still, the attack vector is network‑based (HTTP) and requires high privilege, meaning that if an attacker gains network access, they can use this weakness to fully compromise Oracle Identity Manager data.

Generated by OpenCVE AI on September 17, 2026 at 06:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a fixed Oracle Identity Manager version when released
  • Restrict HTTP access to the Identity Manager to trusted networks or VPNs using firewall rules or segmentation
  • Enforce multi‑factor authentication and the principle of least privilege for all Identity Manager users
  • Continuously monitor system logs for anomalous access patterns or unauthorized data modifications

Generated by OpenCVE AI on September 17, 2026 at 06:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access in Oracle Identity Manager Legacy UI

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Identity Manager accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:30:19.362Z

Reserved: 2026-08-13T18:41:45.892Z

Link: CVE-2026-73943

cve-icon Vulnrichment

Updated: 2026-09-16T15:08:08.454Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:45.310

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-73943

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T06:15:04Z

Weaknesses