CVE-2026-71047
moderateLow-Privilege Takeover Flaw in Oracle Identity Manager 12.2.1.4.0 / 14.1.2.1.0
CVE-2026-71047 is a high-severity (CVSS 8.8) vulnerability in the Core component of Oracle Identity Manager, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It is easily exploitable by an attacker who already holds low-privileged credentials and has network access to the OIM HTTP interface, requiring no user interaction. A successful attack allows complete takeover of Oracle Identity Manager with high impact to confidentiality, integrity, and availability — particularly damaging because OIM centrally manages identities and provisioning, so compromise can cascade into downstream applications and directories. Organizations running the affected on-premises OIM versions in enterprise Fusion Middleware deployments are at risk, especially where the OIM console or SOAP/REST endpoints are reachable by broad user populations. The flaw is not currently listed in CISA's KEV catalog and no public proof-of-concept is known, suggesting no observed in-the-wild exploitation at this time.
What to do: Apply the Oracle Critical Patch Update that remediated this CVE to both OIM 12.2.1.4.0 and 14.1.2.1.0 environments as soon as possible. Restrict network access to OIM HTTP endpoints so that only trusted users and networks can reach the console and service interfaces, and audit low-privileged OIM accounts for recent privilege changes or suspicious activity. Review identity provisioning logs and downstream connected systems for signs of unauthorized account creation or modification that would indicate post-compromise abuse.
| Oracle Identity Manager (Oracle Fusion Middleware, Core component) | 12.2.1.4.0, 14.1.2.1.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.