Junglewise Threat Intelligence

CVE-2026-46807: Oracle Identity Manager auth bypass in OIM Legacy UI

CVE-2026-46807 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Vendors: Oracle.

Executive brief

Oracle Identity Manager, a tool used by organizations to manage user identities and access rights, contains a critical security flaw in its legacy user interface. An unauthorized person can use this flaw over the network to take complete control of the system without needing a username or password. This could lead to a total loss of data confidentiality, unauthorized changes to user permissions, and disruption of identity management services.

Technical details

A critical vulnerability exists in the OIM Legacy UI component of Oracle Identity Manager (part of Oracle Fusion Middleware). The flaw is classified as a missing authentication for a critical function (CWE-306). It is remotely exploitable without authentication via the T3 or IIOP protocols. An attacker can leverage this vulnerability to achieve a complete takeover of the Identity Manager instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. Users should refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle June 2026 Critical Patch Update released

References