SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60535 2026-07-21

CVE-2026-60535: Critical Unauthenticated Takeover in Oracle Identity Manager Connector

"A critical (CVSS 9.8) vulnerability in Oracle Identity Manager Connector lets an unauthenticated, network-based attacker fully compromise the component, addressed in Oracle's July 2026 Critical Patch Update."

A critical (CVSS 9.8) vulnerability in Oracle Identity Manager Connector lets an unauthenticated, network-based attacker fully compromise the component, addressed in Oracle's July 2026 Critical Patch Update.

What Is It

CVE-2026-60535 is a critical vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Oracle describes it as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector. A successful attack can result in complete takeover of the connector. It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting high impact to confidentiality, integrity, and availability.

Why It Matters

The vulnerability requires no authentication, no privileges, and no user interaction, and is reachable over the network via HTTP with low attack complexity. Oracle characterizes it as "easily exploitable," and successful exploitation yields full takeover of the affected connector; meaning an attacker could seize control of an identity management integration point. Because Identity Manager components broker access across enterprise systems, a compromise here has outsized consequences for the surrounding environment.

What's Vulnerable

The affected product is Oracle Identity Manager Connector (vendor: Oracle Corporation), within Oracle Fusion Middleware. The supported versions listed as affected are:

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Organizations running the affected versions should apply the fixes provided in that advisory. No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the source material at this time.

Sources