Vulnerability in Oracle Identity Manager Connector by Oracle
CVE-2026-60991

7.8HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60991?

An access control vulnerability exists in the Oracle Identity Manager Connector component of Oracle Fusion Middleware. This issue is present in the supported versions 12.2.1.4.0 and 14.1.2.1.0. An attacker with low privileges can exploit this vulnerability by gaining access to the infrastructure where the Oracle Identity Manager Connector runs. Successful exploitation may allow the attacker to take control of the Oracle Identity Manager Connector, potentially compromising sensitive data and affecting the overall integrity and availability of the system.

Affected Version(s)

Oracle Identity Manager Connector 12.2.1.4.0

Oracle Identity Manager Connector 14.1.2.1.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.