CVE-2026-60990
9.9Oracle · Identity Manager Connector
A critical vulnerability in the Oracle Identity Manager Connector allows a low privileged attacker to achieve full system takeover via network exploitation.
Executive summary
A low privileged remote attacker can exploit a critical vulnerability in the Oracle Identity Manager Connector to achieve complete system takeover and impact wider infrastructure.
Vulnerability
This vulnerability resides in the Core component and requires the attacker to hold low privileges to initiate the attack. Once triggered, the flaw allows for a complete compromise of the Identity Manager Connector, with potential for scope change affecting connected middleware products.
Business impact
The CVSS 3.1 base score of 9.9 highlights the extreme risk associated with this vulnerability, as it allows for full system takeover. A compromise of the Identity Manager Connector often grants attackers control over identity lifecycle management, potentially leading to widespread unauthorized access across the entire enterprise identity infrastructure.
Remediation
Immediate Action: Update the Oracle Identity Manager Connector to the latest vendor recommended version as specified in the August 2026 security alert.
Proactive Monitoring: Monitor for anomalous administrative activity or privilege escalation attempts within the identity management environment.
Compensating Controls: Restrict network access to the Identity Manager Connector to authorized subnets only and employ strict segmentation to limit the impact of potential lateral movement.
Exploitation status
Public Exploit Available: false
Analyst recommendation
The potential for total system takeover makes this a high priority for security teams. Administrators should audit all current deployments of the affected connectors and apply the necessary patches immediately to secure the identity management architecture.