Description
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Oracle Identity Manager Connector allows an attacker who has access to the physical communication segment to gain unauthenticated control over the component, potentially executing arbitrary code and taking over the connector. This flaw is presented as an Improper Authentication issue, as the connector does not enforce authentication for traffic originating from the local physical network, which can be exploited by a low-entropy, high-complexity attack path. The result is a significant breach of confidentiality, integrity, and availability for the Managed Identity Operator and related user data.

Affected Systems

Affected are Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0 which run in Oracle Fusion Middleware. Any system where these connectors are deployed, particularly those connected to local hardware or network segments with unchecked physical access, is at risk.

Risk and Exploitability

The CVSS score of 8.3 (AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H) indicates a high severity for remote attackers, but the EPSS score of <1% shows a low current exploit probability. It is not listed in the CISA KEV catalog. The path requires the attacker to physically interact or be near the hardware segment that hosts the connector, but once done, no explicit authentication is needed, and the risk extends beyond the connector to other product components due to scope change.

Generated by OpenCVE AI on September 17, 2026 at 04:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Identity Manager Connector to a patched version that addresses this authentication flaw.
  • Restrict physical network access to the segment where the connector runs, using VLANs or firewall rules, to reduce the likelihood of an adjacent network attacker gaining localhost-level visibility.
  • If a patch is not yet available, isolate the connector from untrusted physical segments and monitor for unauthenticated traffic to detect potential exploitation attempts.

Generated by OpenCVE AI on September 17, 2026 at 04:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Oracle Identity Manager Connector Enables Takeover
Weaknesses CWE-287

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager Connector
CPEs cpe:2.3:a:oracle:identity_manager_connector:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager_connector:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager Connector
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:26:04.288Z

Reserved: 2026-08-31T15:40:57.332Z

Link: CVE-2026-83026

cve-icon Vulnrichment

Updated: 2026-09-16T15:43:18.213Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:10.600

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83026

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:30:08Z

Weaknesses