Junglewise Threat Intelligence

CVE-2026-35267: Oracle Identity Manager compromise in REST WebServices

CVE-2026-35267 · Severity: high · CVSS 8.8 · Published 2026-06-17

Vendors: Oracle.

Executive brief

Oracle Identity Manager, a tool used by organizations to manage user identities and access rights, contains a security vulnerability in its web services component. An attacker with basic user credentials can exploit this flaw over the network to take full control of the system. This could lead to unauthorized access to sensitive corporate data, disruption of identity services, and the ability to manipulate user accounts across the enterprise.

Technical details

A vulnerability in the REST WebServices component of Oracle Identity Manager (part of Oracle Fusion Middleware) is classified as a missing authentication for critical function (CWE-306). The flaw allows a low-privileged attacker with network access via HTTP to bypass security controls and achieve a complete takeover of the Identity Manager instance. The vulnerability is considered easily exploitable with a low attack complexity and no user interaction required. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. Organizations should refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle June 2026 Critical Patch Update

References