ZeroHour

CVE-2026-73942

moderate

Low-Privilege Account Takeover in Oracle Identity Manager Legacy UI

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

An easily exploitable flaw in the OIM Legacy UI component of Oracle Identity Manager, part of Oracle Fusion Middleware, allows a low-privileged authenticated attacker with HTTP network access to fully compromise the OIM server. Successful attacks result in complete takeover of Oracle Identity Manager, with high impact on the confidentiality, integrity, and availability of the identity platform. Affected deployments are Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 where the Legacy UI is reachable by untrusted or low-trust users. Because OIM centrally manages user accounts and entitlements, compromise can cascade into unauthorized access across connected enterprise applications and directories. No public proof of concept is known and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, so exploitation is not confirmed in the wild.

What to do: Apply the Oracle Critical Patch Update (CPU) that remediates CVE-2026-73942 to all OIM 12.2.1.4.0 and 14.1.2.1.0 environments as soon as it is available. Until patched, restrict network access to the OIM Legacy UI to trusted admin networks, or disable the Legacy UI entirely if the modern interface meets operational needs. Review low-privileged OIM accounts and audit logs for anomalous privilege changes or account creation that could indicate an attempted takeover.

Affected
Oracle Identity Manager (Oracle Fusion Middleware, component: OIM Legacy UI)
Estimated exposure
moderateLow thousands of internet-reachable OIM systems (order of magnitude ~1,000–10,000 exposed), plus an unknown number of internal-only deployments — Oracle Identity Manager is enterprise identity-governance middleware typically deployed by mid-to-large organizations rather than mass-market software, and public internet scans generally show only low thousands of exposed Oracle Fusion…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.