CVE-2026-34290

7.5

Oracle · Identity Manager Connector

An unauthenticated, network-based vulnerability in the Oracle Identity Manager Connector allows a remote attacker to cause a denial of service via a repeatable crash or system hang.

Executive summary

A critical denial of service vulnerability in the Oracle Identity Manager Connector allows unauthenticated remote attackers to disrupt system availability.

Vulnerability

This vulnerability resides in the core component of the Oracle Identity Manager Connector and is accessible via TCP. An unauthenticated attacker can trigger a crash or hang of the service, resulting in a complete denial of service.

Business impact

The ability for an unauthenticated attacker to remotely crash critical identity management infrastructure presents a significant operational risk. Successful exploitation results in system downtime, which can disrupt authentication services, impede user access to enterprise resources, and force emergency recovery efforts. Given the CVSS score of 7.5, this high-severity flaw requires immediate attention to ensure business continuity.

Remediation

Immediate Action: Consult the Oracle Critical Patch Update advisory for April 2026 to identify and apply the specific security patch for version 12.2.1.4.0.

Proactive Monitoring: Monitor network traffic for unusual TCP activity directed at the Identity Manager Connector and review system logs for recurring service crashes or unexpected process termination.

Compensating Controls: Deploy network-level access control lists or a firewall to restrict access to the Identity Manager Connector ports to known, trusted IP addresses, effectively limiting the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The high severity of this vulnerability, combined with the ease of exploitation for unauthenticated remote attackers, necessitates prompt remediation. Organizations should prioritize patching the affected Oracle Identity Manager Connector instance as soon as the vendor update is applied to prevent potential service disruptions.

More Oracle CVEs

Sources