Summary
This vulnerability affects Oracle Identity Manager and Oracle Web Services Manager via the REST WebServices and Web Services Security interfaces. The root cause is missing authentication for a critical function, allowing an unauthenticated remote attacker to trigger remote code execution over HTTP. Exploitation is possible without user credentials, potentially leading to full takeover of Identity Manager and Web Services Manager.
Why Fix Soon?
4/6Exploitation Details
Takeover of Oracle Identity Manager and Oracle Web Services Manager; full compromise of systems and data; remote code execution with system-level privileges.
Affected Software
| Product | Affected Versions |
|---|---|
| Oracle Identity Manager; Oracle Web Services Manager | 12.2.1.4.0 and 14.1.2.1.0 for Identity Manager; 12.2.1.4.0 and 14.1.2.1.0 for Web Services Manager |
Oracle Identity Manager (OIM) and Oracle Web Services Manager (OWSM) are components of Oracle Fusion Middleware used for identity management and web services security management across enterprise environments.
Affected ComponentREST WebServices interface (Identity Manager) and Web Services Security component (Web Services Manager)
REST WebServices interface (Identity Manager) and Web Services Security component (Web Services Manager)
Not available
Not available
Not available
No known threat actors
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Affected Software (CPE) (4)
- •cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
- •cpe:2.3:a:oracle:web_services_manager:12.2.1.4.0:*:*:*:*:*:*:*
- •cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
- •cpe:2.3:a:oracle:web_services_manager:14.1.2.1.0:*:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| nvd.nist.gov | https://nvd.nist.gov/vuln/detail/CVE-2026-21992 |
| www.oracle.com | https://www.oracle.com/security-alerts/alert-cve-2026-21992.html |
| www.darkreading.com | https://www.darkreading.com/vulnerabilities-threats/patch-oracle-fusion-middleware-rce-flaw |
Priority History
Initial analysis
Reassessed to Planned Fix