CVE-2026-70915
8.8Oracle · Identity Manager
A critical vulnerability in Oracle Identity Manager allows low privileged attackers to achieve full system takeover via network protocols T3 and IIOP.
Executive summary
A high severity vulnerability in Oracle Identity Manager enables authenticated attackers to compromise the entire system, posing a significant risk to organizational identity and access management.
Vulnerability
This vulnerability exists within the Core component of Oracle Identity Manager and is exploitable by an attacker with low-level privileges. By leveraging network access via T3 or IIOP protocols, an attacker can bypass security controls to gain full control over the application.
Business impact
The CVSS 3.1 base score of 8.8 reflects the high potential for total system compromise, including the loss of confidentiality, integrity, and availability. Successful exploitation allows unauthorized actors to control identity management workflows, potentially leading to widespread unauthorized access across the enterprise, data exfiltration, and significant operational disruption.
Remediation
Immediate Action: Review the official Oracle Security Alert for September 2026 to identify and apply the necessary patches or configuration changes provided by the vendor.
Proactive Monitoring: Monitor network traffic for anomalous activity involving T3 or IIOP protocols directed at Oracle Identity Manager instances.
Compensating Controls: Restrict network access to the affected T3 and IIOP ports to known, trusted management segments to limit the attack surface while awaiting patch application.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for full system takeover, organizations running the affected versions of Oracle Identity Manager must prioritize this vulnerability. It is critical to apply vendor-supplied updates as soon as they are made available to prevent unauthorized access and maintain the integrity of your identity infrastructure.
More Oracle CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
- Oracle Advisory Vendor advisory