Cyber & AI intelligence
Wasteland.
Briefs indexed2663
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-83027 2026-09-15

Oracle Identity Manager Connector Hit With Critical 9.3 Adjacent-Network Flaw

"Oracle disclosed CVE-2026-83027, a critical unauthenticated vulnerability in the Oracle Identity Manager Connector that, per Oracle's own assessment, could allow an attacker on the same physical network segment to gain…"

Oracle disclosed CVE-2026-83027, a critical unauthenticated vulnerability in the Oracle Identity Manager Connector that, per Oracle's own assessment, could allow an attacker on the same physical network segment to gain read/write control of connector-accessible data and impact adjacent products.

What Is It

CVE-2026-83027 is a vulnerability in the Core component of Oracle Identity Manager Connector, part of Oracle Fusion Middleware. Oracle rates it CVSS 3.1 base score 9.3 (CRITICAL) with vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N.

The flaw is described as easily exploitable. An unauthenticated attacker with access to the physical communication segment attached to the hardware running the connector can compromise it; no credentials, no user interaction, low attack complexity.

Why It Matters

Two things push this beyond a normal middleware bug.

First, the scope is changed (S:C). Oracle explicitly notes that while the vulnerability lives in Oracle Identity Manager Connector, attacks may significantly impact additional products. The scope-change rating implies that a successful exploit would likely not stay contained to the vulnerable component, though the specific blast radius will depend on the deployment.

Second, the impact is total on both confidentiality and integrity. Successful attacks allow unauthorized creation, deletion, or modification of critical data, or all connector-accessible data, plus unauthorized access to critical data or complete access to all connector-accessible data. Availability is not impacted (A:N).

This is identity infrastructure. A component that provisions and synchronizes accounts being fully writable by an unauthenticated adjacent attacker would plausibly open a path to account manipulation across whatever that connector touches, depending on how it is integrated.

The mitigating factor is the attack vector: AV:A (adjacent network) means the attacker must already have a foothold on the local communication segment. This is not internet-reachable by default.

What's Vulnerable

Oracle lists the following supported versions of Oracle Identity Manager Connector as affected:

Vendor: Oracle Corporation. Product family: Oracle Fusion Middleware.

Patch Status

Oracle published this through its security alerts channel. Administrators should confirm the applicable advisory for their deployment on Oracle's security alerts page and apply the referenced fixes for the affected versions.

The CVE record was published 2026-09-15 and remains in Received status in NVD, meaning NVD analysis is not yet complete. Exploitation status is not established in the sources reviewed here; check the CISA KEV catalog directly for the current entry status before making prioritization decisions.

Sources