Junglewise Threat Intelligence

CVE-2026-60535: Oracle Identity Manager Connector takeover in PeopleSoft Applications

CVE-2026-60535 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle Identity Manager Connector (PeopleSoft Applications). Vendors: Oracle.

Executive brief

A critical vulnerability has been identified in the Oracle Identity Manager Connector for PeopleSoft Applications, which is used to manage user identities and access across enterprise systems. An unauthenticated attacker can exploit this flaw over the network to gain full control of the connector. This could lead to a total compromise of identity management operations, potentially allowing unauthorized access to sensitive corporate data and systems.

Technical details

This vulnerability affects the PeopleSoft Applications component of the Oracle Identity Manager Connector in versions 12.2.1.4.0 and 14.1.2.1.0. It is classified as easily exploitable, requiring no authentication or user interaction (CVSS 9.8). An attacker with network access via HTTP can exploit this flaw to achieve a complete takeover of the Oracle Identity Manager Connector, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Identity Manager Connector (PeopleSoft Applications) 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle and NVD publication.
  • 2026-07-21: advisory

References

Related threats