SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60531 2026-07-21

CVE-2026-60531: Critical Oracle Identity Manager Connector Takeover Flaw

"Oracle's July 2026 Critical Patch Update discloses CVE-2026-60531, a CVSS 9.9 vulnerability in Oracle Identity Manager Connector that lets a low-privileged network attacker fully take over the component and impact…"

Oracle's July 2026 Critical Patch Update discloses CVE-2026-60531, a CVSS 9.9 vulnerability in Oracle Identity Manager Connector that lets a low-privileged network attacker fully take over the component and impact adjacent systems.

What Is It

CVE-2026-60531 is a critical vulnerability in the Core component of Oracle Identity Manager Connector, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows a low-privileged attacker with network access via HTTP to compromise the Connector. Successful exploitation can result in complete takeover of Oracle Identity Manager Connector.

The CVSS 3.1 base score is 9.9 (CRITICAL), with vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.

Why It Matters

This is a near-maximum severity flaw. The attack vector is the network, complexity is low, no user interaction is required, and only low privileges are needed; a combination that makes exploitation straightforward. Critically, the scope is Changed: while the vulnerability resides in Oracle Identity Manager Connector, Oracle warns that attacks "may significantly impact additional products." Because identity management infrastructure governs access across an environment, a compromise here can cascade beyond the vulnerable component itself, threatening the confidentiality, integrity, and availability of connected systems.

What's Vulnerable

The affected product is Oracle Identity Manager Connector (component: Core) within Oracle Fusion Middleware. Per Oracle, the supported versions affected are:

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Administrators should apply the fixes published in that Critical Patch Update to affected Oracle Identity Manager Connector deployments. No confirmed active exploitation is documented in the supplied source material, and there is no CISA KEV entry accompanying this record.

Sources