Junglewise Threat Intelligence

CVE-2026-70915: Oracle Identity Manager remote code execution in T3/IIOP protocol handler

CVE-2026-70915 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Oracle Identity Manager, a core component of Oracle Fusion Middleware used to manage user identities and access rights across enterprises, contains a critical vulnerability allowing attackers with network access to completely compromise the system. An attacker with low-level credentials can exploit the T3 and IIOP protocol handlers to gain full control, potentially exposing or modifying all identity and access data managed by the system.

Technical details

This vulnerability is a remote code execution flaw in the Oracle Identity Manager Core component affecting versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability is exploitable over the network via T3 (Oracle Tuxedo protocol) or IIOP (Internet Inter-ORB Protocol) by attackers with low-level privileges and requires no user interaction. Successful exploitation results in complete takeover of the Oracle Identity Manager process, allowing an attacker to execute arbitrary code with the privileges of the Identity Manager service account, potentially compromising all managed identities and access policies. No patch status is currently available from the advisory text.

Affected products

  • Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-09-15: disclosed

References