Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote System Takeover
Action: Immediate Patch
AI Analysis

Impact

Unauthenticated attackers with HTTP network access can compromise the Oracle Identity Manager Legacy UI, allowing full takeover of the system. The vulnerability is caused by authentication bypass weaknesses (CWE‑287 and CWE‑306) that allow an attacker to authenticate without credentials. This leads to exposure of all confidentiality, integrity, and availability aspects and is scored 9.8 on the CVSS 3.1 scale.

Affected Systems

Oracle Corporation’s Oracle Identity Manager product versions 12.2.1.4.0 and 14.1.2.1.0 are affected.

Risk and Exploitability

The EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation, yet the CVSS score reflects that an attacker who succeeds will gain complete control. The vulnerability is not yet listed in CISA’s KEV catalog. Exploitation requires only unauthenticated HTTP access to the Legacy UI and does not demand privileged credentials or additional preconditions.

Generated by OpenCVE AI on September 20, 2026 at 10:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle’s latest patch for Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 to address the unauthenticated access flaw.
  • Restrict external HTTP access to the OIM Legacy UI by placing it behind a firewall or internal VPN and disabling public exposure if it is not required.
  • Enforce strong authentication, such as two‑factor authentication, for all access to the Legacy UI and ensure that no anonymous or default accounts remain active.

Generated by OpenCVE AI on September 20, 2026 at 10:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access in Oracle Identity Manager Legacy UI Leading to System Takeover

Thu, 17 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access in Oracle Identity Manager Legacy UI Leading to System Takeover

Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-306

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T22:54:37.707Z

Reserved: 2026-08-31T15:40:57.334Z

Link: CVE-2026-83042

cve-icon Vulnrichment

Updated: 2026-09-15T22:45:50.455Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:12.633

Modified: 2026-09-22T19:08:44.153

Link: CVE-2026-83042

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T10:45:18Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function