External risk intelligence

Oracle Identity Manager Unauthenticated Network Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-70913

Oracle Identity Manager is an identity and access management solution. These platforms are commonly deployed as public-facing gateways or identity portals to support remote user authentication and self-service, and the vulnerability specifically allows unauthenticated access via HTTP, indicating it is designed to be reachable over the network.

Authentication Bypass

Oracle Identity Manager

12.2.1.4.014.1.2.1.0

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in Oracle Identity Manager, a product used for managing user identities and access. This issue, if exploited, could allow an attacker to take complete control of the system without needing any prior authentication.

  • Unauthenticated attackers can take over Oracle Identity Manager.
  • Identity and access systems are critical for business operations.
  • Confirm relevance and potential exposure of this product.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can reach Oracle Identity Manager over the network and compromise it. Successful exploitation can lead to a full takeover of the identity management system.

  • Network access is required.
  • Attacker triggers vulnerability via HTTP.
  • Risk of complete system takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access to fully compromise Oracle Identity Manager. This means an attacker could potentially take over the entire system, affecting its confidentiality, integrity, and availability.

  • Oracle Identity Manager system access at risk.
  • Unauthenticated network access can lead to compromise.
  • Complete system takeover is a realistic consequence.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Oracle Identity Manager requires immediate attention from teams responsible for identity and access management solutions. The first step is to determine the scope of affected systems, confirm their accessibility and business criticality, identify the accountable owner, and then prioritize remediation based on this risk assessment.

  • Accountable team: Identity and Access Management.
  • Verify: Network reachability and business criticality.
  • Action: Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Identity Manager used for?

Oracle Identity Manager is a core component of Oracle Fusion Middleware designed to govern user identities, manage access rights, and automate administrative tasks across an enterprise. It functions as a centralized gateway to ensure users have appropriate permissions for various applications and data resources.

What does CWE-287 and CWE-306 mean for CVE-2026-70913?

These codes represent Authentication Bypass and Missing Authentication for Critical Function weaknesses. In the context of CVE-2026-70913, they signify that the system fails to properly verify the identity of a user before granting access, effectively allowing an attacker to interact with sensitive administrative features as if they were a logged-in user.

How is CVE-2026-70913 triggered?

An attacker triggers this vulnerability by sending specifically crafted HTTP requests to the Oracle Identity Manager component over the network. It does not require the attacker to have a valid account or pre-existing credentials; however, the vulnerability cannot be triggered if the system is completely isolated from the network.

Is my Oracle Identity Manager at risk?

Halo Surface Signal indicates that because this product often acts as a public-facing portal for remote access, it is highly likely to be reachable over the network. If your instance is internet-facing or accessible to untrusted network segments, it is at higher risk of being reached by an unauthorized party.

What should I do if I run Oracle Identity Manager?

Prioritize identifying all running instances of versions 12.2.1.4.0 and 14.1.2.1.0 within your environment. Confirm which systems are reachable over the network and establish communication with your identity and access management team to assess the criticality of those assets and plan for applying official security updates.

References