SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60990 2026-08-18

CVE-2026-60990: Critical Oracle Identity Manager Connector Takeover Flaw

"Oracle disclosed a CVSS 9.9 vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware that lets a low-privileged network attacker take over the product and impact adjacent systems."

Oracle disclosed a CVSS 9.9 vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware that lets a low-privileged network attacker take over the product and impact adjacent systems.

What Is It

CVE-2026-60990 is a critical flaw in the Core component of Oracle Identity Manager Connector, part of Oracle Fusion Middleware. Per the vulnerability record, the issue is easily exploitable: an attacker with low privileges and network access over TLS can compromise the Connector without any user interaction. Successful exploitation is characterized as capable of resulting in takeover of Oracle Identity Manager Connector.

The CVSS 3.1 base score is 9.9 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network attack vector, low complexity, low privileges required, no user interaction, changed scope, and high impact to confidentiality, integrity, and availability.

Why It Matters

The scope change is the key detail. The record explicitly notes that while the vulnerability lives in Oracle Identity Manager Connector, attacks may significantly impact additional products. A changed scope means a compromise is not necessarily contained to the vulnerable component; impact may extend past the security boundary into other components the Connector interacts with. How far that reach goes in any given deployment depends on how the Connector is integrated and privileged.

That matters more than usual for an identity management product. The impact profile is high across all three of confidentiality, integrity, and availability, and the barrier to entry is low: any account with minimal privileges and network reachability qualifies.

There is no CISA KEV entry for this CVE in the supplied data, so active exploitation is not confirmed at this time. The 9.9 score, low attack complexity, and identity-layer positioning make it a priority regardless.

What's Vulnerable

Patch Status

The CVE was published 2026-08-18 with NVD status Received, analysis is not yet complete. Patch availability is not confirmed in the supplied data.

One caveat on sourcing: the reference supplied with this record points to an August 2026 Oracle Critical Patch Update advisory. Oracle ships security fixes on a quarterly CPU cycle in January, April, July, and October, and publishes off-cycle fixes as Security Alerts rather than as a CPU. An August CPU does not fit that cadence, and the supplied path could not be verified, so treat the specific advisory reference as unconfirmed. The vulnerability details themselves, score, vector, component, and affected versions, are internally consistent.

Practically, that means a fix for this issue would be expected in the October 2026 CPU unless Oracle issues an out-of-cycle Security Alert. Administrators should locate the authoritative advisory through Oracle's security alerts index and confirm coverage for their specific version rather than relying on the supplied reference. No CISA-mandated remediation deadline is present in the supplied data.

Sources