Description
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-09-15
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is an access control flaw (CWE‑284) that allows an unauthenticated attacker with network access to an Oracle Identity Manager Connector instance to gain unauthorized access to all data managed by the connector. The flaw can lead to the disclosure of sensitive information or complete compromise of data handled by the connector, creating a significant confidentiality risk.

Affected Systems

Affected are Oracle Corporation’s Oracle Identity Manager Connector product in Fusion Middleware, specifically the versions 12.2.1.4.0 and 14.1.2.1.0.

Risk and Exploitability

According to the CVSS 3.1 base score of 8.6, the vulnerability is high severity with a substantial confidentiality impact. The EPSS score of less than 1% indicates a low and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote via HTTP to the connector’s interface, and the flaw’s scope change enables attackers to impact other components beyond the connector itself. Successful exploitation would provide an attacker full read access to protected data.

Generated by OpenCVE AI on September 17, 2026 at 04:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Identity Manager Connector to a patched version newer than 12.2.1.4.0 or 14.1.2.1.0, where the access control flaw is resolved.
  • If an upgrade cannot be performed immediately, restrict network exposure of the connector by allowing HTTP traffic only from trusted hosts or secure VPNs, effectively blocking unauthenticated attackers.
  • Continuously monitor the connector’s logs for unauthorized access attempts and verify that any such attempts are being denied, ensuring the protection of sensitive data.

Generated by OpenCVE AI on September 17, 2026 at 04:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Compromise in Oracle Identity Manager Connector

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle identity Manager Connector
CPEs cpe:2.3:a:oracle:identity_manager_connector:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager_connector:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager Connector
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Identity Manager Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:26:21.088Z

Reserved: 2026-08-31T15:40:57.331Z

Link: CVE-2026-83023

cve-icon Vulnrichment

Updated: 2026-09-16T15:56:38.647Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:10.243

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83023

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:30:08Z

Weaknesses