Junglewise Threat Intelligence

CVE-2026-60532: Oracle Identity Manager Connector compromise in PeopleSoft Applications

CVE-2026-60532 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle Identity Manager Connector (PeopleSoft Applications). Vendors: Oracle.

Executive brief

A critical vulnerability exists in the Oracle Identity Manager Connector for PeopleSoft Applications, which is used to manage user identities and access across enterprise systems. An unauthenticated attacker can exploit this flaw over the network to gain full control of the connector. This could lead to unauthorized access to sensitive personnel data, disruption of identity management services, and potential lateral movement within the corporate network.

Technical details

This vulnerability affects the PeopleSoft Applications component of the Oracle Identity Manager Connector. It is characterized by a high ease of exploitability, requiring no authentication or user interaction (CVSS 3.1 score of 9.8). An attacker with network access via HTTP can exploit this flaw to achieve a complete takeover of the affected component, impacting confidentiality, integrity, and availability. The vulnerability is present in versions 12.2.1.4.0 and 14.1.2.1.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Identity Manager Connector (PeopleSoft Applications) 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60532
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats