Junglewise Threat Intelligence

CVE-2026-83042: Oracle Identity Manager unauthenticated remote code execution in Legacy UI

CVE-2026-83042 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Identity Manager is a critical identity and access management system used to manage user identities and permissions across enterprise systems. This vulnerability allows an unauthenticated attacker with network access to remotely take over the entire Identity Manager system without authentication, potentially exposing or compromising all managed identities and access credentials.

Technical details

An easily exploitable vulnerability in the Oracle Identity Manager Legacy UI component allows unauthenticated remote attackers to achieve complete system compromise via HTTP. The vulnerability requires no authentication, no special privileges, and no user interaction to exploit. Successful attacks result in full takeover of the Identity Manager instance, enabling attackers to read, modify, or delete identity data, manipulate access permissions, and disrupt identity management operations. Patches are expected to be available from Oracle.

Affected products

  • Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-09-15: disclosed

References