Junglewise Threat Intelligence

CVE-2026-60536: Oracle Identity Manager Connector data exposure in PeopleSoft Applications

CVE-2026-60536 · Severity: high · CVSS 8.6 · Published 2026-07-21

Technologies: Oracle Identity Manager Connector. Vendors: Oracle.

Executive brief

A high-severity vulnerability has been identified in the Oracle Identity Manager Connector, specifically within the PeopleSoft Applications component. This software is used to manage user identities and access rights across different enterprise systems. An unauthenticated attacker could exploit this flaw over the network to gain unauthorized access to sensitive corporate data, potentially impacting other connected business systems.

Technical details

This vulnerability exists in the PeopleSoft Applications component of the Oracle Identity Manager Connector within Oracle Fusion Middleware. It is classified as easily exploitable, requiring no authentication or user interaction (AV:N/AC:L/PR:N/UI:N). The flaw allows an attacker to gain unauthorized access to all data accessible by the connector. Notably, the vulnerability involves a scope change (S:C), meaning a successful exploit can impact security domains beyond the Identity Manager Connector itself. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. Users should refer to the Oracle July 2026 Critical Patch Update for remediation guidance.

Affected products

  • Oracle Oracle Identity Manager Connector 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: disclosed: Initial publication of the CVE record.
  • 2026-07-21: advisory: Oracle released the July 2026 Critical Patch Update.

References

Related threats