CVE-2026-70915
moderateAuthenticated Takeover of Oracle Identity Manager via T3/IIOP
CVE-2026-70915 is a high-severity flaw (CVSS 3.1: 8.8) in the Core component of Oracle Identity Manager, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It is triggered remotely by a low-privileged (authenticated) attacker who has network access to the OIM server over the T3 or IIOP protocols, which are Oracle WebLogic communication channels. Because the vulnerability is easily exploitable with no user interaction, a successful attack allows the attacker to fully compromise and take over the Oracle Identity Manager installation, with high impact on confidentiality, integrity, and availability. Since OIM is an identity governance platform, its compromise can also cascade into broader account and access-control abuse across dependent systems. No public proof of concept is known and the flaw is not on the CISA KEV list, so exploitation in the wild is not currently evidenced.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-70915 to all Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 deployments as soon as the fix for your release line is available. Until patched, block T3 and IIOP traffic at the network perimeter so only trusted administration hosts can reach OIM/WebLogic managed-server ports, and disable IIOP entirely if it is not required. Review low-privileged OIM accounts and authentication logs for anomalous logins or privilege changes that could indicate exploitation attempts.
| Oracle Identity Manager (Oracle Fusion Middleware, component: Core) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.