External risk intelligence

Oracle Identity Manager Legacy UI RMI Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-61066

The vulnerability involves RMI (Remote Method Invocation), which is typically used for internal application communication within enterprise environments. While network-reachable, RMI services are not standard public-facing web endpoints and are usually restricted by internal network controls, making broad public internet exposure less common than web-facing services.

Oracle Identity Manager

12.2.1.4.014.1.2.1.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Identity Manager, a component of Oracle Fusion Middleware. This issue allows a low-privileged attacker with network access to potentially take over the system, which could have significant impacts on related products.

  • Low-privilege access grants system takeover.
  • Affects identity management, a critical business function.
  • Confirm relevance and assess potential system-wide impact.

Attack Path

How an attacker could exploit the issue

An attacker with limited privileges could exploit this vulnerability by reaching Oracle Identity Manager over the network via RMI. This would allow them to compromise the system, potentially impacting other products. Successful exploitation could lead to a complete takeover of Oracle Identity Manager, affecting confidentiality, integrity, and availability.

  • Network access with low privileges.
  • Attacker triggers vulnerability via RMI.
  • Full takeover of Identity Manager.

Live Threat

Current exploitation, exposure, and threat context

A vulnerability in Oracle Identity Manager's legacy user interface could allow a low-privileged attacker with network access via RMI to gain complete control of Oracle Identity Manager, and potentially impact other connected products. This could lead to the compromise of sensitive identity and access management data and configurations.

  • System data and user data.
  • Via network access using RMI.
  • Takeover of Oracle Identity Manager.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Oracle Identity Manager impacts Oracle Fusion Middleware and could lead to a complete takeover of the affected system. Given the RMI-based exploitation vector, the first practical step is to identify all instances of Oracle Identity Manager within your environment, determine their network accessibility, and confirm their business criticality. Subsequently, engage the accountable application owners and infrastructure teams to assess the risk and plan remediation, which may involve vendor coordination or temporary risk reduction measures if immediate patching is not feasible.

  • Application and infrastructure owners should manage this.
  • Verify Oracle Identity Manager's network exposure and criticality.
  • Plan remediation based on risk and asset ownership.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Identity Manager and its OIM Legacy UI component?

Oracle Identity Manager is a core component of Oracle Fusion Middleware used by organizations to automate and manage user access rights across IT systems. The OIM Legacy UI is a specific interface within this software suite designed to handle identity administration tasks. It acts as a bridge for managing user identities and provisioning permissions, making it a central control point for security access within enterprise environments.

What does it mean that CVE-2026-61066 allows a system takeover?

A system takeover indicates that an unauthorized user can gain full control over the application. In the context of CVE-2026-61066, this means an attacker could bypass standard security controls to manage or modify the system as if they were a legitimate administrator. Because this involves identity management software, the attacker might gain the ability to create, delete, or alter user accounts and permissions, which could negatively affect the confidentiality and integrity of the entire environment.

How is the vulnerability triggered via RMI?

The vulnerability is triggered when an attacker with existing low-level network access sends specific commands to the Oracle Identity Manager via Remote Method Invocation (RMI). RMI is a protocol that allows a program to invoke methods on an object residing in a different memory space. This flaw is not triggered by standard web browser traffic or typical HTTP requests; it specifically requires interaction with the application's RMI-based communication pathways.

Is my Oracle Identity Manager instance at risk?

According to Halo Surface Signal, this vulnerability relies on RMI, which is typically used for internal application communication. While it is technically network-reachable, RMI services are rarely exposed directly to the public internet. Your risk is generally higher if these services are accessible beyond your trusted internal network boundaries or if the specific management ports are unintentionally exposed to broader network segments.

What steps should I take if I run Oracle Identity Manager?

Begin by identifying every instance of Oracle Identity Manager currently deployed in your environment. Confirm which systems are running the affected versions, 12.2.1.4.0 or 14.1.2.1.0, and determine their network reachability. Coordinate with your infrastructure and application owners to assess the business impact of these instances. Once mapped, prioritize these assets for vendor-provided updates and explore network-level restrictions to limit access to RMI interfaces until a permanent fix is applied.

References