Vulnerability in Oracle Identity Manager of Oracle Fusion Middleware
CVE-2026-60330

8.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60330?

A vulnerability exists within the Oracle Identity Manager component of Oracle Fusion Middleware that allows an attacker with low privileges and network access to exploit the system. This vulnerability primarily affects versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Identity Manager. Although it may be challenging to exploit, the potential impact of a successful attack includes the complete takeover of Oracle Identity Manager, which can consequently affect other components within the Oracle Fusion Middleware ecosystem. The implications on confidentiality, integrity, and availability are significant.

Affected Version(s)

Oracle Identity Manager 12.2.1.4.0

Oracle Identity Manager 14.1.2.1.0

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.