Vulnerability in Oracle Identity Manager Connector by Oracle
CVE-2026-60531

9.9CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60531?

A vulnerability exists in the Oracle Identity Manager Connector component of Oracle Fusion Middleware, impacting supported versions 12.2.1.4.0 and 14.1.2.1.0. This flaw allows a low privileged attacker with network access via HTTP to exploit the connector, potentially leading to a complete takeover. Although the vulnerability is localized to the Oracle Identity Manager Connector, its impact may extend to other products due to a change in scope during an attack. Organizations using affected versions are advised to implement patches and take immediate action to mitigate risks associated with this vulnerability.

Affected Version(s)

Oracle Identity Manager Connector 12.2.1.4.0

Oracle Identity Manager Connector 14.1.2.1.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.