A critical (CVSS 9.8) unauthenticated remote vulnerability in Oracle Identity Manager allows a network attacker to fully compromise and take over the product.
What Is It
CVE-2026-60329 is a vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware, specifically in the OIM Legacy UI component. According to Oracle's NVD record, the flaw is easily exploitable and allows an unauthenticated attacker with network access via T3 or IIOP to compromise Oracle Identity Manager. A successful attack can result in complete takeover of Oracle Identity Manager.
The issue carries a CVSS 3.1 Base Score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting network attack vector, low complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.
Why It Matters
Oracle Identity Manager governs identity and access management, so a full takeover of the product has serious downstream implications for the environment it protects. With no authentication and no user interaction required, and the maximal impact rating across all three security properties, this vulnerability represents a high-priority exposure for any organization running an affected version reachable over T3 or IIOP.
No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the wild at this time based on the source material.
What's Vulnerable
Per Oracle's advisory data, the affected supported versions of Oracle Identity Manager (vendor: Oracle Corporation) are:
- 12.2.1.4.0
- 14.1.2.1.0
The vulnerable component is the OIM Legacy UI, exploitable via the T3 and IIOP protocols.
Patch Status
The vulnerability is addressed in Oracle's July 2026 Critical Patch Update. Organizations running affected versions should consult the Oracle Critical Patch Update advisory and apply the relevant fixes. No separate CISA KEV remediation deadline was included in the supplied source material.
Sources
- Oracle Critical Patch Update Advisory (July 2026), https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60329, https://nvd.nist.gov/vuln/detail/CVE-2026-60329