A critical, network-exploitable flaw in Oracle Identity Manager lets an unauthenticated attacker fully compromise the product over HTTP, earning a maximum-tier CVSS 3.1 score of 9.8.
What Is It
CVE-2026-61196 is a vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware, specifically within the OIM Legacy UI component. Per Oracle's advisory, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful exploitation can result in complete takeover of the product. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting full impact to confidentiality, integrity, and availability.
Why It Matters
With a base score of 9.8 (CRITICAL), this is about as severe as a vulnerability gets. It requires no authentication, no user interaction, and only low attack complexity; an attacker needs only network reachability to the affected HTTP interface. Because Oracle Identity Manager governs identity and access management, a takeover of the product carries downstream risk across whatever systems it provisions and controls. The exploitability sub-score is a maximum 3.9.
What's Vulnerable
The affected product is Oracle Identity Manager (vendor: Oracle Corporation). The supported versions listed as affected are:
- 12.2.1.4.0
- 14.1.2.1.0
The vulnerable component is the OIM Legacy UI.
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running the affected versions should apply the fixes referenced in Oracle's Critical Patch Update advisory. No CISA KEV entry accompanies the supplied source material, so active exploitation is not confirmed here; however, given the 9.8 severity and unauthenticated attack profile, prompt patching is strongly warranted.
Sources
- Oracle Critical Patch Update Advisory – July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-61196, https://nvd.nist.gov/vuln/detail/CVE-2026-61196