Junglewise Threat Intelligence

CVE-2026-60323: Oracle Identity Manager data compromise in OIM Legacy UI

CVE-2026-60323 · Severity: high · CVSS 8.1 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle Identity Manager, a tool used to manage user identities and access rights across an organization, contains a security vulnerability in its legacy user interface. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive data. This could lead to the unauthorized viewing, modification, or deletion of critical identity and access information, potentially compromising the organization's entire security directory.

Technical details

This vulnerability exists in the OIM Legacy UI component of Oracle Identity Manager. It is classified as an easily exploitable flaw that requires low-privileged authentication and network connectivity via HTTP. An attacker can achieve high impacts on confidentiality and integrity by gaining unauthorized access to or modifying all data accessible to Oracle Identity Manager. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0. While the specific CWE is not detailed in the advisory, the impact suggests an authorization or access control failure. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: advisory: Initial publication of the vulnerability by Oracle and NVD.

References