ZeroHour

CVE-2026-83023

moderate

Unauthenticated Data Exposure in Oracle Identity Manager Connector (Core)

CVSS 3.1
8.6 high
EPSS
Published
()
Modified
AI analysis

Oracle Identity Manager Connector, part of Oracle Fusion Middleware (Core component), contains an easily exploitable flaw in supported versions 12.2.1.4.0 and 14.1.2.1.0 that allows an unauthenticated attacker with network access via HTTP to compromise the connector. Successful attacks result in unauthorized access to critical data or complete access to all data the connector can reach, and because the vulnerability carries a scope change (S:C), the impact can extend to additional products beyond the connector itself. The flaw affects confidentiality only (CVSS 3.1: 8.6, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N), so it does not directly enable code execution or data modification. Organizations running either affected version in their Oracle Identity Manager deployments are exposed, particularly where connector endpoints are reachable over the network. No public proof of concept is known, the issue is not on the CISA KEV list, and there is no evidence of exploitation in the wild.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83023 to Oracle Identity Manager Connector on both 12.2.1.4.0 and 14.1.2.1.0, following the version guidance in Oracle's advisory. Until patched, restrict HTTP/network access to OIM and connector endpoints via firewall allow-listing or VPN-only access. Review logs for unauthenticated HTTP requests to connector endpoints and investigate anomalous data access, since this flaw is confidentiality-focused and may also affect systems beyond the connector due to the scope change.

Affected
Oracle Identity Manager Connector (Oracle Fusion Middleware, component: Core)
Estimated exposure
moderate≈1,000s of enterprise OIM deployments worldwide, only a small fraction internet-exposed — Oracle Identity Manager is on-premises identity-governance middleware deployed mainly by mid-size and large enterprises rather than a mass-market product, and public internet scans typically show only low thousands of exposed Oracle…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.