Unauthenticated Access Vulnerability in Oracle Identity Manager Connector by Oracle
CVE-2026-83023

8.6HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-83023?

The vulnerability in Oracle Identity Manager Connector allows unauthenticated attackers with network access via HTTP to exploit the system. This could lead to unauthorized access to critical data, putting sensitive information at significant risk. The affected versions, 12.2.1.4.0 and 14.1.2.1.0, highlight the urgent need for organizations using Oracle Fusion Middleware to address this security issue proactively. It is crucial to take protective measures to mitigate potential attacks that could compromise the integrity and confidentiality of data managed by the Oracle Identity Manager Connector.

Affected Version(s)

Oracle Identity Manager Connector 12.2.1.4.0

Oracle Identity Manager Connector 14.1.2.1.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.