Junglewise Threat Intelligence

CVE-2026-73943: Oracle Identity Manager authentication bypass in Legacy UI

CVE-2026-73943 · Severity: high · CVSS 7.6 · Published 2026-09-15

Executive brief

Oracle Identity Manager is a critical system used by enterprises to manage user identities, access permissions, and authentication across applications. This vulnerability allows a high-privileged attacker with network access to bypass security controls and gain unauthorized access to sensitive identity data or modify user records. Successful exploitation could compromise the security of downstream systems that rely on Identity Manager for authentication and access control.

Technical details

This is an authentication/authorization bypass vulnerability in the OIM Legacy UI component of Oracle Identity Manager affecting versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability is exploitable over the network via HTTP and requires the attacker to already possess high-level privileges. The flaw allows attackers to read sensitive identity data and modify system records, with the vulnerability having a scope change indicating potential impact on dependent systems. No patch status is indicated in the advisory; users should consult Oracle's security update channels for remediation guidance.

Affected products

  • Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-09-15: disclosed

References