A critical (CVSS 9.8) flaw in Oracle Identity Manager Connector lets an unauthenticated attacker take over the component over the network via HTTP, disclosed in Oracle's July 2026 Critical Patch Update.
What Is It
CVE-2026-60532 is a vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware, specifically in the PeopleSoft Applications component. Oracle describes it as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the connector. A successful attack results in full takeover of the Oracle Identity Manager Connector.
Why It Matters
The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. It requires no authentication, no user interaction, and low attack complexity, while delivering high impact to confidentiality, integrity, and availability. Because Oracle Identity Manager governs identity and access, a takeover of its connector poses a serious risk to the trust and access boundaries it enforces.
What's Vulnerable
- Product: Oracle Identity Manager Connector (Oracle Fusion Middleware)
- Component: PeopleSoft Applications
- Affected versions: 12.2.1.4.0 and 14.1.2.1.0
Patch Status
The vulnerability was published on 2026-07-21 and addressed in Oracle's July 2026 Critical Patch Update. Administrators should apply the fixes referenced in the Oracle Critical Patch Update advisory (cpujul2026) for the affected versions. No CISA KEV entry was supplied with this record, so there is no confirmation of active exploitation in the provided source material.