ZeroHour

CVE-2026-83042

moderate

Unauthenticated Remote Takeover in Oracle Identity Manager Legacy UI

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83042 is an easily exploitable vulnerability in the OIM Legacy UI component of Oracle Identity Manager, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. An unauthenticated attacker with network access via HTTP can trigger the flaw and achieve a complete takeover of Oracle Identity Manager, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 9.8, vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Oracle has not disclosed the precise flaw class, but the pre-authentication attack path makes internet-exposed OIM consoles the primary risk. Because OIM is an identity and access management hub, compromise can expose credentials, provisioning workflows, and connected directory integrations across the enterprise. There is no known public proof-of-concept, the CVE is not on the CISA KEV list, and no in-the-wild exploitation has been reported as of this analysis.

What to do: Apply Oracle's latest Critical Patch Update to Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 as soon as it becomes available, since Oracle remediates these flaws through quarterly CPUs. Until patched, restrict network access to the OIM Legacy UI so it is not reachable from untrusted networks, enforce TLS, and place the console behind a VPN or reverse proxy with authentication. Review OIM logs for unauthenticated HTTP requests to legacy UI endpoints and watch for anomalous account, connector, or provisioning changes that could indicate compromise.

Affected
Oracle Identity Manager (Oracle Fusion Middleware, OIM Legacy UI component)12.2.1.4.0, 14.1.2.1.0
Estimated exposure
moderatelow thousands of internet-exposed OIM consoles; overall installed base likely in the thousands to low tens of thousands of enterprise deployments — Oracle Identity Manager is enterprise middleware typically deployed in the thousands at large organizations, and public internet scans for exposed Oracle OIM login/console endpoints historically show on the order of a few thousand…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.