CVE-2026-83025
moderateUnauthenticated data access and manipulation flaw in Oracle Identity Manager Connector
CVE-2026-83025 is a difficult-to-exploit, unauthenticated vulnerability in the Core component of Oracle Identity Manager Connector, part of Oracle Fusion Middleware. A remote attacker with TCP network access to the connector, without any credentials or user interaction, could compromise the connector and — because the vulnerability has a scope change — significantly impact additional products beyond the connector itself. Successful exploitation yields unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to critical data or all data accessible through the Oracle Identity Manager Connector. Affected installations are those running supported versions 12.2.1.4.0 or 14.1.2.1.0. No public proof of concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83025 to all installations of Oracle Identity Manager Connector running 12.2.1.4.0 or 14.1.2.1.0. In the interim, restrict TCP network access to the connector to trusted hosts only via firewall rules and ACLs, since exploitation requires network reachability but no authentication. Audit connector-accessible data and adjacent Fusion Middleware systems for unauthorized modifications or access, keeping in mind the scope change means impacts may extend beyond the connector itself.
| Oracle Identity Manager Connector (Fusion Middleware, component: Core) | 12.2.1.4.0, 14.1.2.1.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.