CVE-2026-83340
Oracle · Identity Manager
A security vulnerability in Oracle Identity Manager allows low privileged attackers to take over the application via HTTP.
Executive summary
A high severity vulnerability in Oracle Identity Manager allows authenticated attackers to perform a full system takeover, posing a significant threat to identity infrastructure.
Vulnerability
This vulnerability exists within the security component of Oracle Identity Manager and is accessible over a network via HTTP. It requires a low privileged user account to trigger, potentially leading to a complete compromise of the identity management system.
Business impact
The ability for a low privileged attacker to take over the identity management system presents a severe risk to organizational security, as this component often controls access to all other enterprise resources. With a CVSS score of 8.8, the vulnerability carries a high risk of total confidentiality, integrity, and availability loss. Successful exploitation could allow an attacker to escalate privileges, manipulate user identities, and bypass existing security controls across the entire network.
Remediation
Immediate Action: Administrators should review the official Oracle Security Alert for the September 2026 cycle and apply the necessary patches to versions 12.2.1.4.0 and 14.1.2.1.0 immediately.
Proactive Monitoring: Monitor access logs for unusual administrative activity or repeated failed attempts to access sensitive security functions within the Identity Manager dashboard.
Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall (WAF) to restrict access to the Identity Manager HTTP interface to known, trusted internal management subnets.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the central role of Identity Manager in enterprise security, this vulnerability must be treated with high priority. Organizations should verify their current versioning and prioritize the deployment of vendor-supplied security updates to prevent unauthorized system takeover.
More Oracle CVEs all →
History
- Collected by CVE Brief via github
- Held for re-check analysis graded thin
- Analyst report written
Sources
- Oracle Advisory Vendor advisory