CVE-2026-35269
Oracle Identity Manager vulnerability analysis and mitigation

Overview

CVE-2026-35269 is an Improper Access Control vulnerability in the REST WebServices component of Oracle Identity Manager, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability allows an unauthenticated remote attacker to perform unauthorized creation, deletion, or modification of critical data accessible to Identity Manager. It was disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU), and carries a CVSS v3.1 base score of 7.5 (High) (Oracle Advisory, Feedly).

Technical details

The root cause is classified as CWE-284 (Improper Access Control), meaning the REST WebServices component of Oracle Identity Manager fails to properly enforce authentication or authorization checks on certain HTTP endpoints (Feedly). An unauthenticated attacker with network access via HTTP can send crafted requests to these exposed REST API endpoints to manipulate identity data without requiring any credentials or user interaction. The attack complexity is low, requires no privileges, and is automatable, making it straightforward to exploit at scale. No public proof-of-concept or detailed technical write-up has been identified at this time (Oracle Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to create, delete, or modify critical data or any data accessible through Oracle Identity Manager, resulting in a high integrity impact. Since Identity Manager is a centralized identity governance platform managing user accounts, roles, and access policies across enterprise systems, unauthorized data modification could enable privilege escalation, account takeover, or disruption of access control across connected systems. Confidentiality and availability are not directly impacted per the CVSS scoring, but integrity compromise in an identity management system can have cascading effects on downstream applications (Oracle Advisory, Feedly).

Mitigation and workarounds

Oracle has released patches for both affected versions (12.2.1.4.0 and 14.1.2.1.0) as part of the June 2026 Critical Security Patch Update, available since June 17, 2026 (Oracle Advisory). Organizations should apply the patch immediately by following the Fusion Middleware patch availability documentation referenced in the advisory. As a temporary workaround, Oracle recommends restricting network access to Identity Manager REST WebServices endpoints to trusted IP ranges only, and monitoring those endpoints for unauthorized modification attempts. Oracle strongly advises against relying on network-level controls as a long-term solution.

Additional resources


SourceThis report was generated using AI

Related Oracle Identity Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61196CRITICAL9.8
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-61197CRITICAL9.1
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-60567CRITICAL9.1
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-60330HIGH8.5
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-60560HIGH8.1
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management