A critical, easily exploitable vulnerability in Oracle Identity Manager allows an unauthenticated attacker with HTTP network access to fully compromise the product, carrying a CVSS 3.1 base score of 9.1.
What Is It
CVE-2026-61197 is a critical vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware, specifically in the OIM Legacy UI component. It is described as easily exploitable and requires no authentication, no privileges, and no user interaction. An attacker with network access via HTTP can leverage the flaw to compromise Oracle Identity Manager. The vulnerability carries a CVSS 3.1 base score of 9.1 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N.
Why It Matters
Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, up to and including all Oracle Identity Manager accessible data, as well as unauthorized read access to critical data or complete access to all OIM accessible data. The confidentiality and integrity impacts are both rated HIGH. Because the flaw is network-reachable and requires no authentication or user interaction, the barrier to exploitation is minimal, making internet-facing OIM deployments especially exposed.
What's Vulnerable
The affected product is Oracle Identity Manager (vendor: Oracle Corporation). The supported versions confirmed as affected are:
- 12.2.1.4.0
- 14.1.2.1.0
The impacted component is the OIM Legacy UI.
Patch Status
Oracle addressed this vulnerability as part of its Critical Patch Update. Administrators should consult the referenced Oracle Critical Patch Update advisory (July 2026) and apply the corresponding fixes. This CVE is not listed in the CISA KEV catalog in the supplied data, so there is no confirmation of active exploitation at this time.
Sources
- Oracle Critical Patch Update Advisory, July 2026, https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-61197, https://nvd.nist.gov/vuln/detail/CVE-2026-61197