CVE-2026-83028
moderateUnauthenticated Takeover Vulnerability in Oracle Identity Manager Connector
CVE-2026-83028 is a difficult-to-exploit, unauthenticated vulnerability in the Core component of the Oracle Identity Manager Connector, part of Oracle Fusion Middleware. Exploitation requires an attacker to have access to the physical communication segment (adjacent network) attached to the hardware where the connector executes — meaning the attacker must already be on the same network segment, such as a compromised host or an insider position in the data center or internal LAN. A successful attack allows complete takeover of the Oracle Identity Manager Connector, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.5). Affected deployments are those running supported versions 12.2.1.4.0 or 14.1.2.1.0. There is no known public proof of concept and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, so exploitation in the wild is not evidenced.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83028 to Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0 as soon as your patch cycle allows. Because exploitation requires adjacency to the connector's network segment, tighten network segmentation and access controls so only trusted hosts can reach the server hosting the connector. Review logs for anomalous connections or credential activity from hosts sharing that segment.
| Oracle Identity Manager Connector (Oracle Fusion Middleware, component: Core) | 12.2.1.4.0, 14.1.2.1.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.