Vulnerability in Oracle Identity Manager Connector of Oracle Fusion Middleware
CVE-2026-60994

7.2HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60994?

A security flaw in the Oracle Identity Manager Connector of Oracle Fusion Middleware allows a low-privileged attacker, with access to the connected infrastructure, to compromise the connector. Exploitation of this vulnerability necessitates human interaction from a third party, resulting in possible unauthorized actions such as the creation, deletion, or modification of critical data. Additionally, it raises the risk of unauthorized access to all data available through the Oracle Identity Manager Connector. The vulnerabilities could lead to significant impacts on related systems and the integrity of critical data.

Affected Version(s)

Oracle Identity Manager Connector 12.2.1.4.0

Oracle Identity Manager Connector 14.1.2.1.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.