CVE-2026-60722

8.8

Oracle · Oracle Identity Manager

A vulnerability in the OIM Legacy UI component of Oracle Identity Manager allows an authenticated attacker with network access via T3 or IIOP protocols to potentially take over the application.

Executive summary

A high severity vulnerability in Oracle Identity Manager permits low privileged attackers to achieve full system takeover via network-based T3 or IIOP protocol exploitation.

Vulnerability

This flaw affects the OIM Legacy UI and is classified as easily exploitable. By using T3 or IIOP protocols, a low privileged user with network access can force the application into an insecure state, resulting in a full system compromise.

Business impact

This vulnerability carries a CVSS score of 8.8, reflecting its potential to cause massive operational disruption and data loss. As Identity Manager often acts as a central authority for user access, a compromise here grants an attacker the ability to escalate privileges across the entire enterprise infrastructure.

Remediation

Immediate Action: Implement the security patches specified in the August 2026 Oracle security advisory to mitigate the risk of system takeover.

Proactive Monitoring: Review system and application logs for unauthorized protocol usage or anomalous service requests that deviate from standard administrative behavior.

Compensating Controls: If patching is delayed, isolate the Identity Manager server at the network level and enforce strict access control lists for all management protocols.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability necessitates immediate attention and the prompt application of vendor patches. Security teams must ensure that all instances of the affected software are updated to the latest secure version to prevent unauthorized system takeover.

More Oracle CVEs