CVE-2026-60720
9.9Oracle · Identity Manager
A critical vulnerability in the Oracle Identity Manager Legacy UI allows a low privileged, network-authenticated attacker to gain full control of the application.
Executive summary
Oracle Identity Manager is susceptible to a critical remote compromise, potentially leading to unauthorized access and full system takeover.
Vulnerability
This vulnerability resides in the OIM Legacy UI component and is exploitable via HTTP. It requires the attacker to have low-level privileges within the system to execute the attack, which subsequently results in a complete compromise of the Identity Manager instance.
Business impact
With a CVSS score of 9.9, this vulnerability represents a critical threat to identity management infrastructure. A compromise of this product likely grants attackers the ability to manipulate user credentials and access rights, leading to cascading security failures across the entire enterprise environment.
Remediation
Immediate Action: Update Oracle Identity Manager to the latest version as directed by the August 2026 Oracle security alert to eliminate the vulnerable Legacy UI code path.
Proactive Monitoring: Monitor HTTP access logs for suspicious requests directed at the Legacy UI components and watch for anomalous administrative actions occurring within the identity platform.
Compensating Controls: Disable the Legacy UI if it is not business-critical or enforce strict IP-based access controls to limit interaction with the affected interface to authorized administrative workstations only.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Identity management systems are high-value targets for attackers. Organizations must apply the vendor patches without delay to prevent the exploitation of this critical flaw and ensure the continued integrity of user access controls.