Unauthenticated Access Vulnerability in Oracle Identity Manager by Oracle
CVE-2026-83422

8.1HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-83422?

An unauthenticated access vulnerability exists in Oracle Identity Manager, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. This flaw enables attackers to exploit the system through network access via HTTP, allowing them to create, delete, or modify data without proper authorization. Although successful exploitation necessitates human interaction—making it less straightforward for attackers—it still poses a significant risk, as it can lead to unauthorized access and manipulation of critical data and resources within the Oracle Identity Manager environment. It is crucial for users and administrators to apply necessary patches and security measures to mitigate this risk.

Affected Version(s)

Oracle Identity Manager 12.2.1.4.0

Oracle Identity Manager 14.1.2.1.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.