CVE-2026-83024
moderateLocal Takeover Flaw in Oracle Identity Manager Connector (Core)
CVE-2026-83024 is an unspecified flaw in the Core component of the Oracle Identity Manager Connector, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It is easily exploitable by a low-privileged attacker who already has logon access to the server or infrastructure where the connector executes, requiring no user interaction. A successful attack allows the attacker to fully compromise the Oracle Identity Manager Connector, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8). Because it requires local authenticated access, the risk is concentrated on hosts where the connector runs and on insiders, compromised low-privilege accounts, or attackers who have already gained a foothold on the infrastructure. There is no known public proof of concept and the CVE is not in CISA's Known Exploited Vulnerabilities catalog as of this analysis.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83024 to Oracle Identity Manager Connector 12.2.1.4.0 and 14.1.2.1.0 environments as soon as the relevant CPU is available. In the interim, harden the hosts where the connector executes: restrict local OS logon to trusted administrative accounts, enforce least-privilege for service and application accounts, and monitor for privilege-escalation or suspicious activity by low-privileged local users.
| Oracle Identity Manager Connector (Oracle Fusion Middleware, component: Core) | 12.2.1.4.0 |
| Oracle Identity Manager Connector (Oracle Fusion Middleware, component: Core) | 14.1.2.1.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.