ZeroHour

CVE-2026-70915

moderate

Authenticated Takeover of Oracle Identity Manager via T3/IIOP

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-70915 is a high-severity flaw (CVSS 3.1: 8.8) in the Core component of Oracle Identity Manager, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It is triggered remotely by a low-privileged (authenticated) attacker who has network access to the OIM server over the T3 or IIOP protocols, which are Oracle WebLogic communication channels. Because the vulnerability is easily exploitable with no user interaction, a successful attack allows the attacker to fully compromise and take over the Oracle Identity Manager installation, with high impact on confidentiality, integrity, and availability. Since OIM is an identity governance platform, its compromise can also cascade into broader account and access-control abuse across dependent systems. No public proof of concept is known and the flaw is not on the CISA KEV list, so exploitation in the wild is not currently evidenced.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-70915 to all Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 deployments as soon as the fix for your release line is available. Until patched, block T3 and IIOP traffic at the network perimeter so only trusted administration hosts can reach OIM/WebLogic managed-server ports, and disable IIOP entirely if it is not required. Review low-privileged OIM accounts and authentication logs for anomalous logins or privilege changes that could indicate exploitation attempts.

Affected
Oracle Identity Manager (Oracle Fusion Middleware, component: Core)
Estimated exposure
moderate≈ a few thousand to low tens of thousands of installations globally — Oracle Identity Manager is an enterprise IAM product deployed mainly in large on-premises environments; internet-wide scans consistently show a subset of WebLogic T3/IIOP endpoints exposed, and OIM instances represent only a fraction of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.