ZeroHour

CVE-2026-83026

moderate

Difficult-to-Exploit Unauthenticated Takeover in Oracle Identity Manager Connector

CVSS 3.1
8.3 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83026 is a high-severity (CVSS 8.3) flaw in the Core component of the Oracle Identity Manager Connector, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It can be triggered by an unauthenticated attacker who has access to the physical communication segment (local/adjacent network) attached to the host where the connector executes; exploitability is rated difficult (high attack complexity). A successful attack results in complete takeover of the Oracle Identity Manager Connector with high confidentiality, integrity, and availability impact, and because of a scope change, attacks may significantly impact additional products beyond the connector itself. Organizations running either affected version in enterprise identity-management deployments are at risk, particularly if network segmentation around OIM infrastructure is weak. There is no known public proof of concept, the flaw is not in the CISA KEV catalog, and no in-the-wild exploitation has been reported.

What to do: Apply Oracle's Critical Patch Update fixes for the Oracle Identity Manager Connector on versions 12.2.1.4.0 and 14.1.2.1.0 as soon as they are available. Enforce strict network segmentation and access controls on the LAN/VLAN segments where OIM Connector servers execute, since exploitation requires adjacency to those hosts. Review logs on connector hosts and connected target systems for anomalous activity, keeping in mind that successful attacks can cascade beyond the connector due to the scope change.

Affected
Oracle Identity Manager Connector (Oracle Fusion Middleware, component: Core)
Estimated exposure
moderatelikely low thousands of enterprise deployments (thousands of OIM installations, mostly on-premises) — Oracle Identity Manager is an enterprise IAM product typically deployed on-premises by large organizations rather than internet-facing hosts, and no public install counts or exposed-device scan data exist, so this is an order-of-magnitude…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.