Oracle disclosed CVE-2026-83027, a critical unauthenticated vulnerability in the Oracle Identity Manager Connector that, per Oracle's own assessment, could allow an attacker on the same physical network segment to gain read/write control of connector-accessible data and impact adjacent products.
What Is It
CVE-2026-83027 is a vulnerability in the Core component of Oracle Identity Manager Connector, part of Oracle Fusion Middleware. Oracle rates it CVSS 3.1 base score 9.3 (CRITICAL) with vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N.
The flaw is described as easily exploitable. An unauthenticated attacker with access to the physical communication segment attached to the hardware running the connector can compromise it; no credentials, no user interaction, low attack complexity.
Why It Matters
Two things push this beyond a normal middleware bug.
First, the scope is changed (S:C). Oracle explicitly notes that while the vulnerability lives in Oracle Identity Manager Connector, attacks may significantly impact additional products. The scope-change rating implies that a successful exploit would likely not stay contained to the vulnerable component, though the specific blast radius will depend on the deployment.
Second, the impact is total on both confidentiality and integrity. Successful attacks allow unauthorized creation, deletion, or modification of critical data, or all connector-accessible data, plus unauthorized access to critical data or complete access to all connector-accessible data. Availability is not impacted (A:N).
This is identity infrastructure. A component that provisions and synchronizes accounts being fully writable by an unauthenticated adjacent attacker would plausibly open a path to account manipulation across whatever that connector touches, depending on how it is integrated.
The mitigating factor is the attack vector: AV:A (adjacent network) means the attacker must already have a foothold on the local communication segment. This is not internet-reachable by default.
What's Vulnerable
Oracle lists the following supported versions of Oracle Identity Manager Connector as affected:
- 12.2.1.4.0
- 14.1.2.1.0
Vendor: Oracle Corporation. Product family: Oracle Fusion Middleware.
Patch Status
Oracle published this through its security alerts channel. Administrators should confirm the applicable advisory for their deployment on Oracle's security alerts page and apply the referenced fixes for the affected versions.
The CVE record was published 2026-09-15 and remains in Received status in NVD, meaning NVD analysis is not yet complete. Exploitation status is not established in the sources reviewed here; check the CISA KEV catalog directly for the current entry status before making prioritization decisions.
Sources
- NVD, CVE-2026-83027: https://nvd.nist.gov/vuln/detail/CVE-2026-83027
- Oracle Security Alerts: https://www.oracle.com/security-alerts/
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog