Junglewise Threat Intelligence

CVE-2026-70913: Oracle Identity Manager unauthenticated remote compromise in HTTP

CVE-2026-70913 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Executive brief

Oracle Identity Manager is a critical identity and access management system used to manage user accounts, roles, and permissions across enterprise applications. This vulnerability allows an attacker with only network access to completely compromise the system without any credentials, potentially granting unauthorized access to all managed identities and systems. An exploit could result in complete takeover of identity management infrastructure, enabling attackers to create backdoor accounts, modify user permissions, or access sensitive employee and customer data.

Technical details

This is an unauthenticated remote code execution or privilege escalation vulnerability in the Core component of Oracle Identity Manager (OIM). The vulnerability is easily exploitable through the HTTP protocol and requires no user interaction or authentication. An attacker with network access can send a crafted HTTP request to compromise the system. Successful exploitation results in complete system compromise with impact to confidentiality, integrity, and availability. The vulnerability affects OIM versions 12.2.1.4.0 and 14.1.2.1.0; patch availability should be confirmed through Oracle security updates.

Affected products

  • Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-09-15: disclosed

References