Unauthenticated Access Vulnerability in Oracle Identity Manager Connector by Oracle
CVE-2026-83027

9.3CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-83027?

A vulnerability exists in the Oracle Identity Manager Connector within Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. This weakness allows an unauthenticated attacker with access to the physical communication segment connected to the hardware running the Oracle Identity Manager Connector to exploit the vulnerability. The implications of successful exploitation can lead to unauthorized creation, deletion, or modification of critical data, thereby compromising the integrity and confidentiality of all accessible data within the Oracle Identity Manager Connector. Moreover, attempts to exploit this vulnerability may have far-reaching consequences, impacting additional products and increasing the overall risk to the network.

Affected Version(s)

Oracle Identity Manager Connector 12.2.1.4.0

Oracle Identity Manager Connector 14.1.2.1.0

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.