External risk intelligence

Oracle Identity Manager OIM Legacy UI Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-61196

Oracle Identity Manager is an identity and access management solution that is typically deployed as a public-facing or edge-accessible service to facilitate user authentication and identity management processes across an organization's network perimeter.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Identity Manager, a product used for managing digital identities and access. This issue could allow an attacker to gain complete control of the system, potentially impacting the confidentiality, integrity, and availability of identity management functions.

  • Unauthenticated attackers can take over Identity Manager.
  • It impacts systems managing user access.
  • Confirm if Identity Manager is in use.

Attack Path

How an attacker could exploit the issue

An attacker could reach Oracle Identity Manager by sending malicious requests over the network. This is possible because the vulnerability is in a component exposed through HTTP, and it allows for unauthenticated access. Successful exploitation could lead to a complete takeover of the identity management system.

  • Entry Condition: Network access, no authentication needed.
  • Trigger Point: Vulnerable Oracle Identity Manager component.
  • Resulting Risk: Full system takeover is possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access to gain complete control over Oracle Identity Manager. This could impact the confidentiality, integrity, and availability of the identity management system.

  • Identity Manager system data at risk.
  • Attacker compromises system via network.
  • Complete takeover of the system.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Oracle Identity Manager likely impacts application owners and infrastructure teams responsible for its deployment and maintenance. The immediate priority should be to identify all instances of the affected technology, assess their reachability and business criticality, and then pinpoint the accountable owner to begin risk-based remediation planning.

  • Application owners and infrastructure teams.
  • Verify affected Oracle Identity Manager instances.
  • Plan remediation based on asset criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Identity Manager and how is it used?

Oracle Identity Manager is a component of Oracle Fusion Middleware designed to manage user identities, access rights, and security policies across an organization. It acts as a central hub for granting or revoking user permissions and ensuring secure access to enterprise applications and data systems.

What kind of vulnerability is CVE-2026-61196?

This vulnerability represents a critical security flaw in the OIM Legacy UI component of Oracle Identity Manager. It allows an attacker to bypass security controls entirely, resulting in a full system takeover. By compromising the interface, an attacker can manipulate the core identity management functions, affecting the confidentiality, integrity, and availability of the entire system.

How does an attacker trigger this vulnerability?

An attacker triggers this flaw by sending specially crafted HTTP requests to the vulnerable OIM Legacy UI component over the network. Crucially, the attacker does not need any valid user credentials or pre-existing access to the system to initiate the attack. Interactions that do not utilize this specific legacy interface or are restricted from network access are not susceptible to this direct trigger path.

Is my system at risk regarding CVE-2026-61196?

If you are running affected versions 12.2.1.4.0 or 14.1.2.1.0, your risk is elevated. According to Halo Surface Signal, this software is frequently deployed as an edge-accessible service to support organizational authentication, meaning it is often intentionally exposed to the network. Any instance reachable over the network should be considered a potential target for unauthenticated actors.

Do I need to take action if I use this software?

Yes, you should prioritize identifying all instances of Oracle Identity Manager within your environment. Verify whether your specific deployment is running the affected versions and assess its reachability from the network. Once mapped, coordinate with your infrastructure and application teams to determine the appropriate remediation steps based on the system's criticality.

References