External risk intelligence

Oracle Identity Manager Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60727

The vulnerability affects the Oracle Identity Manager component, which is an identity and access management portal. These systems are designed to be internet-facing or exposed to network users for authentication and identity management, and the vulnerability allows unauthenticated access via HTTP.

Oracle Identity Manager

12.2.1.4.014.1.2.1.0

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in Oracle Identity Manager could allow an unauthorized attacker to gain complete control of the system. The issue is easily exploitable over the network, meaning successful attacks could lead to a full compromise of identity management functions. The primary concern is to confirm if this specific Oracle product is in use and assess potential exposure.

  • Unauthenticated attackers can fully control Identity Manager.
  • Identity management systems are critical to business operations.
  • Confirm relevance and assess exposure to this identity risk.

Attack Path

How an attacker could exploit the issue

An attacker can target Oracle Identity Manager by sending malicious requests over the network. Since no authentication is required, an unauthenticated attacker can exploit this vulnerability through HTTP to gain complete control of the Oracle Identity Manager system.

  • Network access required.
  • Exploited via unauthenticated HTTP requests.
  • Results in Oracle Identity Manager takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access to compromise Oracle Identity Manager, potentially leading to a complete takeover of the system. This could impact the confidentiality, integrity, and availability of the identity management service.

  • Identity Manager system data.
  • Attacker gains network access via HTTP.
  • Full takeover of Oracle Identity Manager.

Operational Fix

Recommended remediation, mitigation, and detection steps

Addressing this critical vulnerability in Oracle Identity Manager requires collaboration between the application owners responsible for Fusion Middleware and the infrastructure or platform teams managing its deployment. The immediate first step is to identify all instances of the affected Oracle Identity Manager, determine their network reachability and business criticality, and then pinpoint the accountable owner for each instance to plan a coordinated remediation effort.

  • Application and Infrastructure teams should own the issue.
  • Verify Oracle Identity Manager network exposure and criticality.
  • Plan and execute remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Identity Manager and its role in Fusion Middleware?

Oracle Identity Manager is a component within Oracle Fusion Middleware used by organizations to centrally manage user identities, access rights, and security policies across enterprise applications. It serves as a core platform for automating user lifecycles, ensuring the right people have the correct level of access to business systems.

What does CVE-2026-60727 mean for system security?

This vulnerability indicates a serious flaw in the OIM Legacy UI component. It is a critical security weakness that allows an attacker to bypass authentication entirely. By sending malicious requests, an unauthorized party can gain full control over the identity management system, effectively compromising the confidentiality, integrity, and availability of all managed user data.

How does an attacker trigger this vulnerability?

An attacker triggers this bug by sending specific, malicious HTTP requests directly to the affected Oracle Identity Manager service over the network. Crucially, the system does not require any prior authentication or special user privileges to be compromised; if the service can receive HTTP traffic from the attacker, the vulnerability can be triggered.

Is my Oracle Identity Manager instance at risk?

If you are running versions 12.2.1.4.0 or 14.1.2.1.0, you are potentially at risk. Halo Surface Signal notes that because this software is frequently positioned to be internet-facing or accessible to broad network segments for user portal functions, the likelihood of an attacker successfully reaching and exploiting this service is very high.

What should I do if I run Oracle Identity Manager?

Your first step is to perform an inventory to locate all active installations of the affected Oracle Identity Manager versions. Once identified, work with your infrastructure and application teams to verify the network reachability of these instances. Prioritize securing any systems that are accessible over the network while preparing to apply official security updates.

References