Description
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation leading to full compromise of Oracle Identity Manager Connector
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in the Oracle Identity Manager Connector product (Oracle Fusion Middleware) allows an attacker who has already logged on to the host machine carrying the connector to compromise the connector process. The flaw is described as an easily exploitable weakness that can lead to a takeover of Oracle Identity Manager Connector, resulting in loss of confidentiality, integrity, and availability for the connector’s function. The CVSS 3.1 base score of 7.8 reflects these impacts.

Affected Systems

The reported affected products are Oracle Identity Manager Connector, versions 12.2.1.4.0 and 14.1.2.1.0. No additional versions are listed.

Risk and Exploitability

The CVSS score indicates moderate to high severity, while the EPSS score of less than 1 % indicates a low probability of exploitation in the wild. The CVE description notes a low privileged attacker with logon to the infrastructure as the required access, implying that exploitation is limited to local hosts where a user is already authenticated; no remote network attack vector is specified.

Generated by OpenCVE AI on September 20, 2026 at 11:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0
  • Reconfigure the connector to enforce stricter access controls and minimize local privileges for the service account
  • Implement host-level security hardening and restrict physical or network logon permissions to trusted administrators

Generated by OpenCVE AI on September 20, 2026 at 11:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Identity Manager Connector

Thu, 17 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Identity Manager Connector

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager Connector
CPEs cpe:2.3:a:oracle:identity_manager_connector:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager_connector:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager Connector
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:26:15.534Z

Reserved: 2026-08-31T15:40:57.332Z

Link: CVE-2026-83024

cve-icon Vulnrichment

Updated: 2026-09-16T15:43:12.382Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:10.360

Modified: 2026-09-22T19:09:42.130

Link: CVE-2026-83024

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T11:45:12Z

Weaknesses