Executive brief
A critical vulnerability exists in the Oracle Identity Manager Connector for PeopleSoft Applications, which is used to manage user identities and access across enterprise systems. An unauthenticated attacker can exploit this flaw over the network to gain full control of the connector. This could lead to unauthorized access to sensitive personnel data, disruption of identity management services, and potential lateral movement within the corporate network.
Technical details
This vulnerability affects the PeopleSoft Applications component of the Oracle Identity Manager Connector. It is characterized by a high ease of exploitability, requiring no authentication or user interaction (CVSS 3.1 score of 9.8). An attacker with network access via HTTP can exploit this flaw to achieve a complete takeover of the affected component, impacting confidentiality, integrity, and availability. The vulnerability is present in versions 12.2.1.4.0 and 14.1.2.1.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Identity Manager Connector (PeopleSoft Applications) 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-60532
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released