Sceawere

Vulnerability Detail

CVE-2026-71111UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Identity Manager Installer Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Identity Manager
Attack Type
Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Identity Manager executes to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager.
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Installer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Identity Manager executes to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-08-18T21:18:11.627Z",
  "pubdate": "2026-08-18T21:18:11.627Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Installer component of Oracle Identity Manager, a core product of Oracle Fusion Middleware. This security flaw impacts supported versions 12.2.1.4.0 and 14.1.2.1.0, posing severe risks to organizational infrastructure. The vulnerability allows an attacker with low privileges and local logon access to the underlying infrastructure where Oracle Identity Manager executes to successfully compromise the application. Successful exploitation of this vulnerability results in a complete takeover of Oracle Identity Manager, granting the adversary absolute control over the targeted system. The severity of this flaw is reflected in its CVSS 3.1 Base Score of 7.8, with high impacts on confidentiality, integrity, and availability. The attack vector is local, requiring low privileges and no user interaction, but yielding maximum operational disruption upon successful execution.",
  "technicalDetails": "The vulnerability resides in the Installer component of Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0. The attack vector is local (AV:L), meaning the adversary must already possess physical or remote interactive logon access to the specific underlying infrastructure where the Oracle Identity Manager service or installation environment executes. The attack complexity is low (AC:L), requiring minimal technical hurdles or specialized conditions for successful exploitation once access to the infrastructure is established. Furthermore, the vulnerability demands only low privileges (PR:L) on the host operating system or environment, and requires no user interaction (UI:N) to execute successfully. The scope of the vulnerability is unchanged (S:U), meaning the impact remains restricted to the vulnerable Oracle Identity Manager component and its direct administrative domain rather than cascading across decoupled security domains.\nThe attack flow begins with the low-privileged attacker establishing an interactive or programmatic session on the infrastructure hosting Oracle Identity Manager. Leveraging insecure configurations, improper permissions, or flawed logic within the Installer component, the attacker interacts with vulnerable installation scripts, binaries, or configuration files managed by the Oracle Identity Manager Installer. By exploiting these weaknesses, the attacker can manipulate execution flows, inject unauthorized administrative directives, or abuse installation mechanisms to elevate privileges within the application context. Because the Installer component often executes with elevated operating system or application-level permissions, successful exploitation circumvents intended authorization boundaries. The post-exploitation impact encompasses a complete takeover of Oracle Identity Manager (C:H, I:H, A:H), allowing the adversary to read, modify, or destroy critical identity repositories, forge authentication credentials, disrupt business-critical identity and access management operations, and subvert the entire security architecture governed by the application."
}
CVE-2026-71111: Oracle Identity Manager Installer Vulnerability (HIGH Severity, CVSS: 7.8) - Sceawere