CVE-2026-61118
8.8Oracle · Identity Manager
A vulnerability in the OIM Legacy UI component of Oracle Identity Manager allows an authenticated attacker with network access to achieve full system takeover.
Executive summary
A high severity vulnerability in Oracle Identity Manager allows a low privileged attacker to compromise the entire system, posing a significant risk to identity infrastructure.
Vulnerability
This is an easily exploitable vulnerability where an attacker with low-level privileges can leverage network access via HTTP to gain unauthorized control over the application.
Business impact
Successful exploitation results in a complete takeover of the Oracle Identity Manager instance. Given its role in managing enterprise identities, this compromise could lead to widespread unauthorized access to downstream applications, data exfiltration, and total loss of administrative control over identity governance. The CVSS score of 8.8 reflects the high potential for impact on confidentiality, integrity, and availability.
Remediation
Immediate Action: Review the official Oracle Security Alert for August 2026 and apply the recommended patches to the affected Identity Manager versions.
Proactive Monitoring: Monitor system access logs for anomalous HTTP requests originating from low privileged user accounts targeting the OIM Legacy UI.
Compensating Controls: Deploy Web Application Firewall rules to inspect and filter suspicious traffic directed at legacy UI endpoints until patches can be applied.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing Oracle Identity Manager must prioritize this update due to the risk of full system compromise. Administrative teams should verify their current versioning and apply vendor-supplied security updates as soon as they are made available to mitigate the potential for unauthorized administrative takeover.