Description
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Component Takeover
Action: Immediate Patch
AI Analysis

Impact

The flaw in Oracle Identity Manager Connector enables an unauthenticated attacker who can reach the physical communication segment attached to the hardware where the connector runs to compromise the component. While the vendor description states only that a takeover is possible, based on the CVSS 3.1 vector (AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H) it is inferred that the attacker may gain full control of the connector, effectively representing a component takeover that could threaten confidentiality, integrity and availability of managed identities.

Affected Systems

Affected are Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0, which are part of Oracle Fusion Middleware. Any deployment where these connector packages are installed and exposed to a local or adjacent network segment constitutes a risk area, especially in environments lacking strict physical access controls.

Risk and Exploitability

The CVSS base score of 8.3 marks the vulnerability as high severity, but the EPSS score of less than 1% indicates a low current exploitation probability. The flaw is not yet listed in the CISA KEV catalog. Exploitation requires an attacker to have physical or adjacent network access, after which authentication is not required; the vulnerability can change scope and potentially affect other products in the environment.

Generated by OpenCVE AI on September 20, 2026 at 12:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle’s official patch that corrects the authentication flaw in the Identity Manager Connector.
  • Enforce strict physical and network isolation for the connector’s communication segment, using VLANs or firewall rules to prevent unauthenticated access from adjacent networks.
  • Implement monitoring and logging on the connector to detect anomalous unauthenticated traffic, and configure intrusion detection to alert on suspicious activity.

Generated by OpenCVE AI on September 20, 2026 at 12:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Title Physical Access Enables Component Takeover of Oracle Identity Manager Connector

Sun, 20 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Oracle Identity Manager Connector Enables Takeover
Weaknesses CWE-287

Thu, 17 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Oracle Identity Manager Connector Enables Takeover
Weaknesses CWE-287

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager Connector
CPEs cpe:2.3:a:oracle:identity_manager_connector:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager_connector:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager Connector
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:26:04.288Z

Reserved: 2026-08-31T15:40:57.332Z

Link: CVE-2026-83026

cve-icon Vulnrichment

Updated: 2026-09-16T15:43:18.213Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:10.600

Modified: 2026-09-22T19:09:31.573

Link: CVE-2026-83026

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T12:45:17Z

Weaknesses