Vulnerability in Oracle Identity Manager Connector for Oracle Fusion Middleware
CVE-2026-60998

8HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60998?

A vulnerability exists in the Oracle Identity Manager Connector, affecting versions 12.2.1.4.0 and 14.1.2.1.0, which could be exploited by an attacker with high privileges and network access through LDAP. This vulnerability allows for unauthorized access to the Oracle Identity Manager Connector, which may lead to potential control over the system. The impact of a successful exploitation can extend to other connected products, increasing the risk to organizational security. It is crucial for users to take proactive measures to secure their implementations and mitigate potential threats.

Affected Version(s)

Oracle Identity Manager Connector 12.2.1.4.0

Oracle Identity Manager Connector 14.1.2.1.0

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.