Vulnerability in Oracle Identity Manager of Oracle Fusion Middleware
CVE-2026-60720

9.9CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60720?

An exploitable vulnerability exists in the Oracle Identity Manager component of Oracle Fusion Middleware, specifically within the OIM Legacy UI. This issue allows a low-privileged attacker with HTTP network access to compromise the Oracle Identity Manager. Although the vulnerability is directly related to Oracle Identity Manager, successful exploitation may have far-reaching implications that affect additional products. Attackers could potentially take control of the Oracle Identity Manager, threatening the confidentiality, integrity, and availability of affected systems.

Affected Version(s)

Oracle Identity Manager 12.2.1.4.0

Oracle Identity Manager 14.1.2.1.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.