Junglewise Threat Intelligence

CVE-2026-35265: Oracle Identity Manager auth bypass in Security component

CVE-2026-35265 · Severity: high · CVSS 8.8 · Published 2026-06-17

Vendors: Oracle.

Executive brief

Oracle Identity Manager, a tool used by organizations to manage user identities and access rights, contains a security vulnerability in its Security component. A low-privileged user with network access can exploit this flaw to take full control of the Identity Manager system. This could lead to unauthorized access to sensitive corporate data, disruption of identity services, and the ability for an attacker to manipulate user permissions across the enterprise.

Technical details

A vulnerability in the Security component of Oracle Identity Manager (part of Oracle Fusion Middleware) is classified as Missing Authentication for Critical Function (CWE-306). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows for a complete takeover of the Identity Manager instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle published security alert cspujun2026.html

References