CVE-2026-83340
moderateLow-Privilege Authenticated Takeover Flaw in Oracle Identity Manager
CVE-2026-83340 is a high-severity (CVSS 3.1: 8.8) vulnerability in the Security component of Oracle Identity Manager, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. The flaw is described by Oracle as easily exploitable by a low-privileged (authenticated) attacker who has network access to the product via HTTP. Successful exploitation allows the attacker to fully compromise — i.e., take over — the Oracle Identity Manager installation, with high impact on the confidentiality, integrity, and availability of the identity management platform. Because OIM centralizes user provisioning and access control, a takeover can cascade into compromised accounts and broader access across dependent enterprise systems. No public proof-of-concept exists, the CVE is not in CISA's Known Exploited Vulnerabilities catalog, and no exploitation in the wild is currently known.
What to do: Apply the Oracle Critical Patch Update (CPU) fix for CVE-2026-83340 to all OIM 12.2.1.4.0 and 14.1.2.1.0 installations as soon as the relevant CPU is available. Restrict HTTP/HTTPS access to OIM consoles and service endpoints to trusted networks and VPNs, audit low-privilege accounts for signs of privilege escalation or unauthorized administrative changes, and verify that no exposed OIM instances are internet-facing.
| Oracle Identity Manager (Oracle Fusion Middleware, component: Security) | 12.2.1.4.0, 14.1.2.1.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.