Unauthenticated Vulnerability in Oracle Fusion Middleware's Identity Manager Connector
CVE-2026-83025

8.7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-83025?

The Oracle Identity Manager Connector within Oracle Fusion Middleware is susceptible to a vulnerability that allows unauthorized network access without authentication. Attackers can exploit this flaw to compromise the connector, potentially leading to unauthorized creation, deletion, or modification of critical data. While the vulnerability directly affects the Identity Manager Connector, it may also impact other products significantly, broadening the scope of risk. Successful exploitation can result in extensive unauthorized access to sensitive information accessible by the connector.

Affected Version(s)

Oracle Identity Manager Connector 12.2.1.4.0

Oracle Identity Manager Connector 14.1.2.1.0

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.