Junglewise Threat Intelligence

CVE-2026-60330: Oracle Identity Manager compromise in OIM Legacy UI

CVE-2026-60330 · Severity: high · CVSS 8.5 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle Identity Manager, a tool used by organizations to manage user identities and access rights, contains a vulnerability in its legacy user interface. A low-privileged user could exploit this flaw to gain full control over the identity management system. Because this system controls access to other corporate resources, a successful attack could allow the intruder to compromise additional connected products and services.

Technical details

A vulnerability exists in the OIM Legacy UI component of Oracle Identity Manager (versions 12.2.1.4.0 and 14.1.2.1.0). The flaw is accessible via the network over HTTP and requires low-privileged authentication. While the attack complexity is rated as high, a successful exploit results in a scope change (S:C), meaning the impact extends beyond the Identity Manager itself to other products in the environment. The vulnerability allows for complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation details.

Affected products

  • Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: advisory: Initial publication of CVE-2026-60330 by Oracle

References