Junglewise Threat Intelligence

CVE-2026-71111: Oracle Identity Manager privilege escalation in Installer

CVE-2026-71111 · Severity: high · CVSS 7.8 · Published 2026-08-18

Vendors: Oracle.

Executive brief

Oracle Identity Manager is an identity and access management system used to manage user accounts and credentials across enterprise infrastructure. A vulnerability in the installer component allows a low-privileged local user to escalate their privileges and take complete control of the Identity Manager system, potentially exposing or modifying sensitive identity data and access controls across the organization.

Technical details

This is a local privilege escalation vulnerability in the Oracle Identity Manager installer component. The vulnerability is easily exploitable and requires only local logon access and low privileges to trigger; no user interaction is needed. A successful exploit allows an attacker to achieve complete compromise of the Oracle Identity Manager system, including confidentiality, integrity, and availability impacts. The affected versions are 12.2.1.4.0 and 14.1.2.1.0. Oracle has released a patch as part of their August 2026 security update.

Affected products

  • Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched

References