
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35268 is an Improper Access Control vulnerability in the Core component of Oracle Identity Manager, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0 and 14.1.2.1.0 and was publicly disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU). The vulnerability carries a CVSS v3.1 base score of 9.9 (Critical), reflecting its network-accessible, low-complexity, low-privilege attack profile with a changed scope (Oracle Advisory, NVD).
The vulnerability is classified as CWE-284 (Improper Access Control) in the Core component of Oracle Identity Manager. It is exploitable over the network via the T3 and IIOP protocols — both commonly used in Oracle WebLogic-based environments for Java RMI and CORBA communications — by a low-privileged authenticated attacker without requiring user interaction. The changed scope indicator in the CVSS vector indicates that successful exploitation can affect resources beyond the Identity Manager instance itself, potentially impacting other connected systems within the Oracle Fusion Middleware ecosystem (Oracle Advisory, NVD).
Successful exploitation results in a complete takeover of Oracle Identity Manager, with high impact to confidentiality, integrity, and availability. Because Identity Manager is a centralized identity governance platform managing user accounts and access across enterprise systems, a compromise can enable lateral movement to connected applications and directories. The changed scope means downstream systems integrated with Identity Manager — such as LDAP directories, HR systems, and enterprise applications — may also be compromised (Oracle Advisory, NVD).
Oracle has released patches for affected versions (12.2.1.4.0 and 14.1.2.1.0) as part of the June 2026 Critical Security Patch Update; customers should apply these patches immediately by consulting the Fusion Middleware patch availability documentation (Oracle Advisory). As a temporary workaround, Oracle recommends blocking network access to T3 and IIOP protocols at the network perimeter or firewall level for Identity Manager hosts, and restricting access to trusted administrative hosts only. Additionally, limiting low-privileged account access to Identity Manager services and monitoring for anomalous authentication activity can reduce risk until patches are applied.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."