Unauthenticated Access Vulnerability in Oracle Identity Manager Connector by Oracle
CVE-2026-60536

8.6HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60536?

The vulnerability in Oracle Identity Manager Connector pertains to an unauthorized access flaw that can be exploited by an unauthenticated attacker with network access via HTTP. This easily exploitable issue affects specific supported versions of the product, namely 12.2.1.4.0 and 14.1.2.1.0. Successful exploitation can lead to unauthorized access to sensitive data or full access to all information the Oracle Identity Manager Connector can access, posing significant risks not only to the connector but potentially to interconnected applications.

Affected Version(s)

Oracle Identity Manager Connector 12.2.1.4.0

Oracle Identity Manager Connector 14.1.2.1.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.