External risk intelligence

Oracle Identity Manager Legacy UI Vulnerability Allows Unauthorized Data Access and Modification

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-61197

Oracle Identity Manager is an identity and access management solution. Such products are typically deployed as public-facing or internet-accessible identity portals to facilitate user authentication and management. The vulnerability is accessible via HTTP without authentication, characterizing it as a pre-authentication service endpoint.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Identity Manager, an Oracle Fusion Middleware product. This issue allows an unauthenticated attacker with network access to potentially alter or access sensitive data within the identity management system. The main concern is to confirm if this specific technology is in use and if it is exposed.

  • Unauthenticated attackers can access sensitive data.
  • Identity management systems control user access.
  • Confirm Oracle Identity Manager use and exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker with network access could target the Oracle Identity Manager's legacy user interface. By exploiting this vulnerability, they could gain unauthorized access to critical data, modify it, or even delete it, leading to a complete compromise of the identity management system.

  • No authentication required.
  • Network access via HTTP.
  • Unauthorized data access and modification.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via HTTP could compromise Oracle Identity Manager, potentially leading to unauthorized access, modification, or deletion of critical data. This could affect system data related to user identities and access privileges within the Oracle Identity Manager environment.

  • Critical identity and access data.
  • Network access via HTTP.
  • Unauthorized access or data modification.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Oracle Identity Manager, accessible externally via HTTP, likely falls under the responsibility of platform or application teams managing identity and access solutions. The immediate first step is to identify all instances of the affected Oracle Identity Manager, determine their exposure and criticality, and then locate the accountable owner to plan remediation based on established risk tolerance.

  • Platform or application owners should address.
  • Verify external accessibility and business criticality.
  • Plan phased remediation and vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Identity Manager and the OIM Legacy UI?

Oracle Identity Manager is a component of Oracle Fusion Middleware designed to manage user identities, access rights, and permissions across an organization. The OIM Legacy UI is a specific interface within this platform that facilitates these administrative and self-service tasks. Because it acts as a central hub for identity data, it is a critical piece of infrastructure that controls who can access other enterprise applications.

What does CVE-2026-61197 mean for system security?

This CVE describes a severe security flaw that allows unauthorized parties to bypass standard login requirements. Because the system fails to verify the identity of the person making the request, an attacker can read, modify, or delete sensitive information stored within the identity manager. This weakness essentially grants an outsider the same power to alter identity records as an administrator, compromising the integrity and privacy of all managed user accounts.

How can an attacker trigger this vulnerability?

An attacker triggers this bug by sending specifically crafted HTTP requests directly to the affected Legacy UI component over a network. Because the vulnerability exists at a pre-authentication endpoint, the attacker does not need a valid user account or password to interact with the system. It is important to note that this is a remote network attack; local access to the server hardware is not required to initiate the exploit.

Is my Oracle Identity Manager instance at risk?

Your risk depends largely on whether your OIM instance is reachable from the network. According to Halo Surface Signal, identity management solutions are frequently deployed as internet-facing portals to support remote user authentication. If your OIM Legacy UI is accessible via the public internet, it faces a higher likelihood of being targeted by unauthorized network traffic compared to instances strictly confined to an internal, isolated network.

What should I do first to address this security issue?

Your first step is to perform a comprehensive inventory to locate all active instances of the affected Oracle Identity Manager software within your environment. Once you have identified these systems, assess their network exposure and business criticality. Coordinate with the teams responsible for these applications to review official security alerts from Oracle and begin planning the necessary updates or configuration changes to mitigate the risk.

References