Executive brief
Oracle Identity Manager, a tool used by organizations to manage user identities and access rights, contains a security vulnerability in its web services component. An attacker with basic user credentials can exploit this flaw over the network to gain full access to sensitive identity data. This could allow an unauthorized person to view, change, or delete critical user information and access permissions across the enterprise.
Technical details
A vulnerability exists in the REST WebServices component of Oracle Identity Manager (versions 12.2.1.4.0 and 14.1.2.1.0). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows for unauthorized confidentiality and integrity impacts, enabling the attacker to read, modify, or delete any data accessible to the Identity Manager service. The attack does not require user interaction and has a CVSS 3.1 base score of 8.1. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: advisory: Initial publication of CVE-2026-60560 by Oracle