Junglewise Threat Intelligence

CVE-2026-35268: Oracle Identity Manager improper access control in Core component

CVE-2026-35268 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle Identity Manager, a tool used by organizations to manage user identities and access rights across their systems. A low-privileged user can exploit this flaw over the network to take full control of the Identity Manager system. Because this component manages access for other applications, a successful attack could allow an intruder to compromise additional connected business systems and data.

Technical details

An improper access control vulnerability (CWE-284) exists in the Core component of Oracle Identity Manager. The flaw is easily exploitable by a low-privileged attacker with network access via the T3 or IIOP protocols. Successful exploitation results in a complete takeover of the Identity Manager instance. Notably, the vulnerability carries a 'Scope Change' (S:C) designation, indicating that an attacker can leverage this compromise to impact other products or security domains beyond Identity Manager itself. Affected versions include 12.2.1.4.0 and 14.1.2.1.0.

Affected products

  • Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References