Executive brief
Oracle Identity Manager is a widely-deployed identity and access management system used to manage user credentials and permissions across enterprise applications. This vulnerability allows a low-privileged authenticated user to gain complete control over the Identity Manager system, potentially leading to unauthorized access to all managed systems and accounts, compromise of user credentials, and denial of service.
Technical details
The vulnerability exists in the Security component of Oracle Identity Manager and is exploitable via HTTP by a low-privileged authenticated user. The flaw allows an attacker with valid credentials and network access to escalate privileges and achieve complete takeover of the Oracle Identity Manager instance. No user interaction is required for exploitation. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0. As of the advisory date, there is no public indication of active exploitation in the wild, though Oracle issued a security patch as part of their September 2026 Critical Patch Update.
Affected products
- Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed