Executive brief
Oracle Identity Manager, a tool used by organizations to manage user identities and access rights, contains a critical security flaw in its legacy user interface. An unauthorized attacker can exploit this over the network to gain full control of the system. This could lead to a total compromise of user credentials, unauthorized access to sensitive corporate resources, and significant operational disruption.
Technical details
This vulnerability exists in the OIM Legacy UI component of Oracle Identity Manager within the Oracle Fusion Middleware suite. It is classified as a critical flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. The exploit is described as 'easily exploitable' and requires no user interaction or special privileges. A successful attack results in a complete takeover of the Oracle Identity Manager instance, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-61196 by Oracle.