External risk intelligence

Oracle Identity Manager Legacy UI Vulnerability Allows Unauthorized Data Access and Modification

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-60567

Oracle Identity Manager is an identity and access management solution that is frequently exposed to the network to provide authentication and identity services. The vulnerability is exploitable via HTTP by an unauthenticated attacker, which is characteristic of a public-facing identity portal or service designed to be reachable for user authentication and management purposes.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability in Oracle Identity Manager, a system for managing user identities and access. The flaw could allow an attacker to gain unauthorized control over sensitive data within the system without needing any credentials.

  • Unauthenticated attackers can alter critical data.
  • Protects identity and access management systems.
  • Confirm exposure of identity management systems.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by sending specially crafted network requests to Oracle Identity Manager via HTTP. This exposure allows them to interact with the OIM Legacy UI component, potentially leading to unauthorized access and manipulation of critical data.

  • Network access required
  • Unauthenticated attacker triggers vulnerability
  • Unauthorized data access and modification

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access could exploit this vulnerability to gain unauthorized access to critical data or all data within Oracle Identity Manager. This could lead to the unauthorized creation, deletion, or modification of data, or complete access to sensitive information managed by the system.

  • Critical data and all accessible data.
  • Network access via HTTP.
  • Unauthorized data modification or access.

Operational Fix

Recommended remediation, mitigation, and detection steps

Oracle Identity Manager administrators and security teams are the primary stakeholders for this vulnerability. The first practical step is to inventory all Oracle Identity Manager instances, determine their network accessibility, and confirm their criticality to business operations. Once identified, the accountable owner should be engaged to assess the risk and plan remediation.

  • Identity and Access Management/Security teams own the issue.
  • Verify network reachability and business criticality.
  • Plan vendor-coordinated remediation or risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Identity Manager and the OIM Legacy UI?

Oracle Identity Manager is a core component of Oracle Fusion Middleware used by organizations to manage user identities, access rights, and security permissions across IT systems. The OIM Legacy UI is a specific interface within this platform that provides users and administrators with tools to interact with these identity functions.

What does this vulnerability mean for CVE-2026-60567?

This vulnerability represents a significant security flaw that allows unauthorized individuals to bypass authentication mechanisms. Essentially, it means that someone without valid login credentials could interact with the identity system to view, delete, or change critical information managed by the software.

How is CVE-2026-60567 triggered?

An attacker triggers this vulnerability by sending specially crafted HTTP requests over a network to the targeted Oracle Identity Manager instance. It is important to note that this flaw does not require the attacker to have pre-existing access, valid accounts, or user interaction to succeed.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal identifies this as a critical concern for systems reachable via the network, such as public-facing identity portals. Because this software is often intentionally exposed to provide authentication services, internet-facing instances are at higher risk of being reached by an unauthenticated attacker.

What should I do if I run Oracle Identity Manager?

Your first step is to catalog all instances of Oracle Identity Manager in your environment to understand which ones are active. Once you have an inventory, assess the network visibility of each system and identify the relevant stakeholders responsible for managing these platforms so they can prepare for vendor-provided updates.

References