CVE-2026-35268
Oracle Identity Manager vulnerability analysis and mitigation

Overview

CVE-2026-35268 is an Improper Access Control vulnerability in the Core component of Oracle Identity Manager, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0 and 14.1.2.1.0 and was publicly disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU). The vulnerability carries a CVSS v3.1 base score of 9.9 (Critical), reflecting its network-accessible, low-complexity, low-privilege attack profile with a changed scope (Oracle Advisory, NVD).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control) in the Core component of Oracle Identity Manager. It is exploitable over the network via the T3 and IIOP protocols — both commonly used in Oracle WebLogic-based environments for Java RMI and CORBA communications — by a low-privileged authenticated attacker without requiring user interaction. The changed scope indicator in the CVSS vector indicates that successful exploitation can affect resources beyond the Identity Manager instance itself, potentially impacting other connected systems within the Oracle Fusion Middleware ecosystem (Oracle Advisory, NVD).

Impact

Successful exploitation results in a complete takeover of Oracle Identity Manager, with high impact to confidentiality, integrity, and availability. Because Identity Manager is a centralized identity governance platform managing user accounts and access across enterprise systems, a compromise can enable lateral movement to connected applications and directories. The changed scope means downstream systems integrated with Identity Manager — such as LDAP directories, HR systems, and enterprise applications — may also be compromised (Oracle Advisory, NVD).

Exploitation steps

  1. Reconnaissance: Identify Oracle Identity Manager instances (versions 12.2.1.4.0 or 14.1.2.1.0) exposed on the network, particularly those with T3 (default port 7001/7002) or IIOP (default port 3700) ports accessible.
  2. Obtain low-privileged credentials: Acquire any valid low-privileged account on the Identity Manager system (e.g., a standard user account), as the vulnerability requires only low privileges.
  3. Connect via T3 or IIOP: Use a Java-based client or tool (e.g., a custom Java RMI client or WebLogic T3 client library) to establish a connection to the Identity Manager server over the T3 or IIOP protocol.
  4. Exploit improper access control: Send crafted requests that exploit the improper access control flaw in the Core component, bypassing authorization checks to access privileged functionality or objects.
  5. Achieve system takeover: Leverage the unauthorized access to execute privileged operations within Identity Manager, potentially including modifying user roles, provisioning accounts, or executing code — resulting in full system compromise and potential lateral movement to connected systems (Oracle Advisory, NVD).

Indicators of compromise

  • Network: Unexpected or anomalous connections to Identity Manager T3 ports (typically 7001, 7002) or IIOP ports (typically 3700) from internal hosts or low-privileged user contexts; unusual volume of T3/IIOP traffic from non-administrative sources.
  • Logs: Identity Manager audit logs showing low-privileged accounts performing administrative or privileged operations; unexpected role assignments, user provisioning events, or policy changes in Identity Manager audit trails.
  • Process/Application: Unexpected changes to Identity Manager configuration, user roles, or connected system connectors; new administrative accounts created without corresponding change management records.
  • Authentication: Low-privileged accounts authenticating to Identity Manager via T3 or IIOP at unusual times or from unexpected source IPs.

Mitigation and workarounds

Oracle has released patches for affected versions (12.2.1.4.0 and 14.1.2.1.0) as part of the June 2026 Critical Security Patch Update; customers should apply these patches immediately by consulting the Fusion Middleware patch availability documentation (Oracle Advisory). As a temporary workaround, Oracle recommends blocking network access to T3 and IIOP protocols at the network perimeter or firewall level for Identity Manager hosts, and restricting access to trusted administrative hosts only. Additionally, limiting low-privileged account access to Identity Manager services and monitoring for anomalous authentication activity can reduce risk until patches are applied.

Additional resources


SourceThis report was generated using AI

Related Oracle Identity Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61196CRITICAL9.8
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-61197CRITICAL9.1
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-60567CRITICAL9.1
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-60330HIGH8.5
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-60560HIGH8.1
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management