ZeroHour

CVE-2026-83025

moderate

Unauthenticated data access and manipulation flaw in Oracle Identity Manager Connector

CVSS 3.1
8.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83025 is a difficult-to-exploit, unauthenticated vulnerability in the Core component of Oracle Identity Manager Connector, part of Oracle Fusion Middleware. A remote attacker with TCP network access to the connector, without any credentials or user interaction, could compromise the connector and — because the vulnerability has a scope change — significantly impact additional products beyond the connector itself. Successful exploitation yields unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to critical data or all data accessible through the Oracle Identity Manager Connector. Affected installations are those running supported versions 12.2.1.4.0 or 14.1.2.1.0. No public proof of concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83025 to all installations of Oracle Identity Manager Connector running 12.2.1.4.0 or 14.1.2.1.0. In the interim, restrict TCP network access to the connector to trusted hosts only via firewall rules and ACLs, since exploitation requires network reachability but no authentication. Audit connector-accessible data and adjacent Fusion Middleware systems for unauthorized modifications or access, keeping in mind the scope change means impacts may extend beyond the connector itself.

Affected
Oracle Identity Manager Connector (Fusion Middleware, component: Core)12.2.1.4.0, 14.1.2.1.0
Estimated exposure
moderate≈thousands to tens of thousands of enterprise deployments (estimate) — Oracle Identity Manager Connector is licensed enterprise identity-governance middleware typically deployed on-premises in large organizations, with limited internet-exposed instances in public scan data, so the reachable population is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.