CVE-2026-73942

Oracle · Identity Manager

A vulnerability in the OIM Legacy UI of Oracle Identity Manager allows an authenticated attacker with low privileges to achieve a full system takeover via HTTP.

Executive summary

A critical vulnerability in Oracle Identity Manager allows low-privileged attackers to gain complete control over the application, posing a severe risk to organizational identity security.

Vulnerability

This flaw exists within the OIM Legacy UI component of Oracle Fusion Middleware. It permits an authenticated attacker with low privileges to compromise the application through network-based HTTP requests, ultimately leading to a full system takeover.

Business impact

The ability for a low-privileged user to achieve a complete takeover of an identity management system represents a catastrophic security failure. Successful exploitation leads to total loss of confidentiality, integrity, and availability for the platform, which likely manages user credentials and access rights across the entire enterprise. With a CVSS base score of 8.8, this high-severity vulnerability must be prioritized to prevent unauthorized administrative control and potential lateral movement within the network.

Remediation

Immediate Action: Review the official Oracle Security Alert for September 2026 and apply the recommended patches or configuration updates provided by the vendor.

Proactive Monitoring: Monitor application access logs for unusual administrative activity, unauthorized privilege escalation, or unexpected HTTP requests originating from low-privileged user accounts.

Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall to filter suspicious HTTP traffic targeting the OIM Legacy UI component until the patch is applied.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

Given the potential for complete system takeover, organizations running the affected versions of Oracle Identity Manager must treat this vulnerability with high urgency. Administrators should prioritize the identification of affected instances and apply the vendor-supplied security updates as soon as they are made available to mitigate the risk of unauthorized system compromise.

More Oracle CVEs all →

History

  1. Collected by CVE Brief via github
  2. Held for re-check analysis graded thin
  3. Analyst report written

Sources