A critical (CVSS 9.8) vulnerability in Oracle Identity Manager Connector lets an unauthenticated, network-based attacker fully compromise the component, addressed in Oracle's July 2026 Critical Patch Update.
What Is It
CVE-2026-60535 is a critical vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Oracle describes it as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector. A successful attack can result in complete takeover of the connector. It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting high impact to confidentiality, integrity, and availability.
Why It Matters
The vulnerability requires no authentication, no privileges, and no user interaction, and is reachable over the network via HTTP with low attack complexity. Oracle characterizes it as "easily exploitable," and successful exploitation yields full takeover of the affected connector; meaning an attacker could seize control of an identity management integration point. Because Identity Manager components broker access across enterprise systems, a compromise here has outsized consequences for the surrounding environment.
What's Vulnerable
The affected product is Oracle Identity Manager Connector (vendor: Oracle Corporation), within Oracle Fusion Middleware. The supported versions listed as affected are:
- 12.2.1.4.0
- 14.1.2.1.0
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Organizations running the affected versions should apply the fixes provided in that advisory. No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the source material at this time.
Sources
- Oracle Critical Patch Update Advisory, July 2026, https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60535, https://nvd.nist.gov/vuln/detail/CVE-2026-60535