Sceawere
Vulnerability Detail
CVE-2026-61196Updated Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Identity Manager Unauthenticated Takeover
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Identity Manager
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-07-21T22:18:51.510Z",
"pubdate": "2026-07-21T22:18:51.510Z",
"executiveSummary": "This vulnerability exists within the OIM Legacy UI component of Oracle Identity Manager (versions 12.2.1.4.0 and 14.1.2.1.0).\nIt is classified as a critical-severity, easily exploitable vulnerability allowing an unauthenticated remote attacker to compromise the application.\nWith a CVSS 3.1 Base Score of 9.8, the vulnerability permits full unauthorized access to the application, impacting Confidentiality, Integrity, and Availability.\nThe attack vector is network-based over HTTP, requiring no user interaction or authentication to initiate.\nSuccessful exploitation results in a complete takeover of Oracle Identity Manager, potentially granting the attacker administrative control over enterprise identity management processes.\nThis flaw presents significant risk, as it allows attackers to bypass security boundaries to access sensitive identity data or modify identity lifecycle configurations.",
"technicalDetails": "The vulnerability resides within the OIM Legacy UI component, which serves as a legacy interface for Oracle Identity Manager. The flaw stems from insufficient input validation or insecure handling of HTTP requests within the authentication or session management pathways of this specific component.\nBecause the vulnerability is rated with an attack complexity of 'Low' (AC:L) and requires no authentication (PR:N), the system fails to verify the identity of the requestor before processing sensitive commands or administrative logic.\nThe exploitation flow begins with an unauthenticated attacker sending a crafted HTTP request directly to the OIM Legacy UI endpoint. Given the nature of the component, the application fails to properly sanitize or authorize the incoming request, allowing the attacker to bypass the standard authentication handshake.\nUpon reaching the vulnerable function, the payload triggers an execution flow that permits the attacker to either manipulate administrative parameters, inject unauthorized commands, or force the application to perform actions with elevated privileges.\nThe attack operates entirely over the network via standard HTTP protocols, making it accessible from any host capable of reaching the Oracle Identity Manager listener. By leveraging this access, an attacker can gain unauthorized read/write access to the backend database or underlying application server environment.\nThe impact of a successful exploit is comprehensive; the 'Takeover' status implies that the attacker can perform arbitrary administrative tasks, such as creating or modifying identity objects, extracting user credentials, or reconfiguring the Identity Manager infrastructure to maintain persistence. The scope (S:U) indicates that the vulnerability is contained within the OIM environment, but its high impacts on CIA (Confidentiality, Integrity, and Availability) underscore the total loss of control over the affected Oracle Identity Manager instance."
}