Unauthenticated Access Vulnerability in Oracle Identity Manager Connector by Oracle
CVE-2026-60533

8HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60533?

The vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware allows an unauthenticated attacker, with access to the physical communication segment connected to the hardware, to exploit the connector. This can lead to unauthorized creation, deletion, or modification of critical data, as well as the potential to cause a denial of service (DOS) by crashing the Oracle Identity Manager Connector. It poses significant risks as it may affect other interconnected products, making it crucial for organizations to address this vulnerability promptly.

Affected Version(s)

Oracle Identity Manager Connector 12.2.1.4.0

Oracle Identity Manager Connector 14.1.2.1.0

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.