Junglewise Threat Intelligence

CVE-2026-61197: Oracle Identity Manager improper access control in OIM Legacy UI

CVE-2026-61197 · Severity: critical · CVSS 9.1 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle Identity Manager, a tool used by organizations to manage user identities and access rights, contains a critical security flaw in its legacy user interface. An unauthorized attacker can exploit this over the network to gain full access to sensitive identity data or modify user permissions. This could lead to a complete compromise of the identity management system, allowing attackers to create, delete, or steal critical corporate data.

Technical details

A vulnerability exists in the OIM Legacy UI component of Oracle Identity Manager (part of Oracle Fusion Middleware). The flaw is categorized as easily exploitable and requires no authentication or user interaction (CVSS 3.1 Base Score 9.1). An attacker can exploit this via HTTP over the network to achieve unauthorized creation, deletion, or modification of all data accessible to Oracle Identity Manager. The exploit also allows for complete unauthorized access to sensitive identity information. The vulnerability affects supported versions 12.2.1.4.0 and 14.1.2.1.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References