Junglewise Threat Intelligence

CVE-2026-83023: Oracle Identity Manager Connector unauthorized data access

CVE-2026-83023 · Severity: high · CVSS 8.6 · Published 2026-09-15

Technologies: Oracle Identity Manager Connector. Vendors: Oracle.

Executive brief

Oracle Identity Manager Connector is a component of Oracle Fusion Middleware used to manage user identities and access across enterprise systems. An unauthenticated attacker with network access can exploit a vulnerability to gain unauthorized access to sensitive identity data without authentication. Successful exploitation could expose critical customer and operational data managed by the identity system.

Technical details

An easily exploitable vulnerability in Oracle Identity Manager Connector (Core component) allows unauthenticated network attackers to bypass access controls via HTTP requests. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0. Successful exploitation results in unauthorized read access to sensitive data, with potential scope change affecting other Oracle Fusion Middleware products. No user interaction or elevated privileges are required for exploitation. Patch availability and remediation guidance should be obtained from Oracle's security advisories.

Affected products

  • Oracle Identity Manager Connector 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-09-15: disclosed

References

Related threats