CVE-2026-73943
moderatePrivileged Data-Access Flaw in Oracle Identity Manager Legacy UI
Oracle Identity Manager (OIM) versions 12.2.1.4.0 and 14.1.2.1.0, part of Oracle Fusion Middleware, contain an easily exploitable vulnerability in the OIM Legacy UI component. A high-privileged attacker with network access via HTTP — with no user interaction and low attack complexity — can compromise Oracle Identity Manager. Due to a scope change, successful attacks may significantly impact additional products beyond OIM itself, resulting in unauthorized access to critical data or complete access to all OIM-accessible data, plus unauthorized update, insert, or delete access to some of that data. Organizations running the affected OIM versions, particularly those with the Legacy UI reachable over the network by privileged users, are at risk. The CVE is not on CISA's KEV list and no public proof of concept is known, so exploitation in the wild is not currently evident.
What to do: Apply Oracle's Critical Patch Update fixes for Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 as soon as they are available. Until patched, restrict network access to the OIM Legacy UI (VPN/IP allowlisting), disable the Legacy UI if it is not required, and prefer the modern UI. Audit high-privileged OIM accounts for misuse and monitor for anomalous bulk reads or unauthorized data modifications across connected applications.
| Oracle Fusion Middleware / Oracle Identity Manager (OIM Legacy UI) | 12.2.1.4.0, 14.1.2.1.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Identity Manager accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.