
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35269 is an Improper Access Control vulnerability in the REST WebServices component of Oracle Identity Manager, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability allows an unauthenticated remote attacker to perform unauthorized creation, deletion, or modification of critical data accessible to Identity Manager. It was disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU), and carries a CVSS v3.1 base score of 7.5 (High) (Oracle Advisory, Feedly).
The root cause is classified as CWE-284 (Improper Access Control), meaning the REST WebServices component of Oracle Identity Manager fails to properly enforce authentication or authorization checks on certain HTTP endpoints (Feedly). An unauthenticated attacker with network access via HTTP can send crafted requests to these exposed REST API endpoints to manipulate identity data without requiring any credentials or user interaction. The attack complexity is low, requires no privileges, and is automatable, making it straightforward to exploit at scale. No public proof-of-concept or detailed technical write-up has been identified at this time (Oracle Advisory).
Successful exploitation allows an unauthenticated attacker to create, delete, or modify critical data or any data accessible through Oracle Identity Manager, resulting in a high integrity impact. Since Identity Manager is a centralized identity governance platform managing user accounts, roles, and access policies across enterprise systems, unauthorized data modification could enable privilege escalation, account takeover, or disruption of access control across connected systems. Confidentiality and availability are not directly impacted per the CVSS scoring, but integrity compromise in an identity management system can have cascading effects on downstream applications (Oracle Advisory, Feedly).
Oracle has released patches for both affected versions (12.2.1.4.0 and 14.1.2.1.0) as part of the June 2026 Critical Security Patch Update, available since June 17, 2026 (Oracle Advisory). Organizations should apply the patch immediately by following the Fusion Middleware patch availability documentation referenced in the advisory. As a temporary workaround, Oracle recommends restricting network access to Identity Manager REST WebServices endpoints to trusted IP ranges only, and monitoring those endpoints for unauthorized modification attempts. Oracle strongly advises against relying on network-level controls as a long-term solution.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."