Unauthenticated Vulnerability in Oracle Identity Manager Connector of Oracle Fusion Middleware
CVE-2026-60993

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60993?

The Oracle Identity Manager Connector within Oracle Fusion Middleware is exposed to an unauthenticated attack due to a vulnerability that can be exploited by an attacker with physical access to the communication segment. This vulnerability permits unauthorized access, potentially leading to full compromise of the Oracle Identity Manager Connector. Versions 12.2.1.4.0 and 14.1.2.1.0 are affected, highlighting the importance of securing network segments and implementing strict physical access controls to mitigate this risk.

Affected Version(s)

Oracle Identity Manager Connector 12.2.1.4.0

Oracle Identity Manager Connector 14.1.2.1.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.