SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60567 2026-07-21

CVE-2026-60567: Critical Unauthenticated Flaw in Oracle Identity Manager

"A critical, easily exploitable vulnerability in Oracle Identity Manager lets unauthenticated attackers compromise the product over the network, earning a CVSS 3.1 base score of 9.1."

A critical, easily exploitable vulnerability in Oracle Identity Manager lets unauthenticated attackers compromise the product over the network, earning a CVSS 3.1 base score of 9.1.

What Is It

CVE-2026-60567 is a critical vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware, specifically in the OIM Legacy UI component. Per Oracle's advisory, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, reflecting network attack vector, low complexity, and no privileges or user interaction required.

Why It Matters

Successful exploitation can result in unauthorized creation, deletion, or modification access to critical data, or all data accessible to Oracle Identity Manager, as well as unauthorized read access up to complete access to all such data. Because Identity Manager governs account and access provisioning, a compromise carries high confidentiality and integrity impact (the CVSS availability impact is rated None). The combination of no authentication, low attack complexity, and a 9.1 score makes this a high-priority exposure for any organization running affected versions.

What's Vulnerable

The affected product is Oracle Identity Manager (Oracle Corporation), component OIM Legacy UI. The supported versions listed as affected are:

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running the affected versions should consult the Oracle Critical Patch Update advisory for July 2026 and apply the provided fixes. No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the provided source material.

Sources