CVE-2026-35265: Oracle Identity Manager Authentication Bypass – Critical Patch Required
Oracle Identity Manager contains a security flaw that allows someone with low-level user access on your network to take over the service entirely. The vulnerability requires only network access and a standard user account—no administrator privileges needed—making it a realistic threat in most enterprise environments. Once exploited, an attacker gains complete control, potentially exposing sensitive identity data and disrupting access management for your entire organization.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.8 HIGH · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-306
- Affected products
- 2 configuration(s)
- Published / Modified
- 2026-06-17 / 2026-06-18
NVD description (verbatim)
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-35265 is a missing authentication or authorization control vulnerability (CWE-306) in Oracle Identity Manager's security component. The flaw permits low-privileged network-authenticated users to execute operations that should require elevated permissions, leading to full system compromise. Affected versions are 12.2.1.4.0 and 14.1.2.1.0. The low attack complexity means exploitation does not require special conditions, timing tricks, or user interaction—a straightforward network request from an authenticated account is sufficient.
Business impact
Compromise of Identity Manager threatens the foundation of your access control infrastructure. An attacker gaining control can create unauthorized user accounts, modify permission assignments, access sensitive identity records, disable legitimate accounts, or introduce persistent backdoors. Given Identity Manager's role in provisioning and authentication across connected systems, a successful attack could enable lateral movement and compromise of downstream applications and data. Recovery typically involves forensic investigation, credential rotation across integrated systems, and potential service downtime during remediation.
Affected systems
Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 are confirmed vulnerable. Organizations running these versions should assume risk until patching is completed. Verify your deployment version in the Identity Manager console or administrative interface. Versions prior to 12.2.1.4.0 and releases after 14.1.2.1.0 should be checked against the vendor advisory to confirm patch status.
Exploitability
This vulnerability is easily exploitable. The attack surface is wide—any user with valid network credentials can attempt exploitation. No special tools, zero-days in other components, or elaborate social engineering is required. The lack of user interaction requirement (UI:N in the CVSS vector) means automated attack tools or simple scripts can trigger the vulnerability. The primary barrier is obtaining a legitimate user credential, which is often available through credential theft, insider threats, or compromise of less-protected accounts.
Remediation
Apply Oracle's security patches for Identity Manager as soon as testing permits. Obtain and review the official Oracle Identity Manager Security Advisory from the June 2026 Critical Patch Update release for your specific version. Patching is the definitive control; workarounds may be available in the advisory but should be considered interim only. After patching, verify the fix by restarting Identity Manager services and confirming version updates in administrative consoles.
Patch guidance
Consult Oracle's Critical Patch Update advisory issued June 17, 2026, for the specific patch version applicable to 12.2.1.4.0 or 14.1.2.1.0. Oracle typically provides patches through their MyOracleSupport portal. Plan a maintenance window with identity and access teams to avoid disruption; Identity Manager restarts may affect user provisioning workflows. Before deploying to production, test patches in a staging environment that mirrors your configuration. Document the pre-patch configuration and have a rollback plan in case of unexpected issues.
Detection guidance
Monitor Identity Manager logs for unusual authentication or authorization failures followed by successful access from low-privileged accounts. Look for users performing administrative operations (account creation, permission modification, role assignment) that deviate from baseline behavior. Check for unexpected API calls or HTTP requests to administrative endpoints from low-privileged users. Network-based detection should flag POST or PUT requests to sensitive Identity Manager endpoints originating from standard user accounts. Consider enabling enhanced audit logging in Identity Manager before patching to establish forensic evidence of any active exploitation.
Why prioritize this
This vulnerability scores 8.8 (HIGH) due to easy exploitability, low privilege requirements, and complete system compromise impact. No user interaction is needed, and the attack surface is broad—any authenticated user becomes a potential attacker. Identity Manager's critical role in enterprise access control makes its compromise a business-critical event. Patching should be prioritized above most other patch management activities.
Risk score, explained
The 8.8 CVSS 3.1 score reflects: (1) network-level attack vector requiring only HTTP and valid credentials; (2) low attack complexity—no special conditions needed; (3) low privilege requirement—standard users can exploit; (4) no user interaction; (5) complete confidentiality, integrity, and availability impacts. The score does not account for environmental factors like network segmentation or compensating controls; organizations with strong authentication requirements or network isolation may reduce practical risk below the base score.
Frequently asked questions
Do we need to patch immediately if Identity Manager is only accessible to trusted internal users?
Yes. While network isolation reduces exposure, the low privilege requirement means internal users or compromised internal accounts are sufficient for exploitation. Insider threats and credential theft are common; assume an attacker will obtain valid credentials eventually. Patch as soon as practically possible.
Can we mitigate this without patching?
Temporary mitigations may exist in Oracle's advisory—such as disabling specific endpoints or enforcing stricter authentication policies—but these are interim measures. They should not delay patching. Mitigations often have operational trade-offs and may not cover all attack paths.
How can we detect if this vulnerability has been exploited in our environment?
Review Identity Manager audit logs for privilege escalation patterns: low-privileged users performing administrative operations, unexpected account creations, or rapid permission modifications. Check access logs for unusual API or HTTP activity to sensitive endpoints. If you suspect exploitation, involve your incident response team and consider forensic analysis of Identity Manager databases and authentication records.
Are versions older than 12.2.1.4.0 or newer than 14.1.2.1.0 safe?
Only the stated versions are confirmed vulnerable. However, verify older and newer releases against Oracle's official advisory to confirm patch status. Do not assume other versions are unaffected until you have reviewed official vendor guidance.
This analysis is based on the official CVE-2026-35265 description and CVSS scoring. Specific patch versions, workarounds, and detailed advisory information must be verified directly with Oracle's Security Advisory. Organizations should test all patches in non-production environments before deployment. Actual risk varies by configuration, network architecture, and compensating controls; consult your security team for environment-specific guidance. This page does not constitute professional security advice or guarantee of patch effectiveness. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-35267HIGHOracle Identity Manager REST WebServices Authentication Bypass (CVSS 8.8)
- CVE-2026-35274HIGHOracle PeopleSoft PT PeopleTools Authentication Bypass
- CVE-2026-35276HIGHOracle PeopleSoft Authentication Bypass Vulnerability (8.1 CVSS)
- CVE-2026-35279HIGHPeopleSoft PT PeopleTools Authentication Bypass – Critical Patch Guidance
- CVE-2026-35289HIGHOracle PeopleSoft PT PeopleTools Authentication Bypass (CVSS 8.1)
- CVE-2026-35295HIGHOracle WebCenter Sites Authentication Bypass – High Risk Patch Alert
- CVE-2026-35299HIGHOracle WebLogic Server Console Authentication Bypass (CVSS 8.8)
- CVE-2026-35303HIGHWebLogic Server Console Vulnerability – Patch & Detection Guide