CVE-2026-35294
Oracle Identity Manager vulnerability analysis and mitigation

Overview

CVE-2026-35294 is an Improper Access Control vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware, specifically in the Mainframe Connectors component. It affects versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Identity Manager Connector. The vulnerability was disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 9.9 (Critical), reflecting its network-accessible, low-complexity attack vector with scope change (Oracle Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control), indicating that the Mainframe Connectors component of Oracle Identity Manager Connector fails to properly enforce access restrictions on HTTP-accessible functionality (Feedly). A low-privileged attacker with network access via HTTP can exploit this flaw without requiring user interaction or elevated privileges, making it easily exploitable. The vulnerability has a changed scope, meaning successful exploitation can extend impact beyond the Identity Manager Connector itself to affect additional products within the Oracle Fusion Middleware ecosystem (Oracle Advisory). No public proof-of-concept or detailed technical write-up has been published as of the disclosure date.

Impact

Successful exploitation results in a complete takeover of the Identity Manager Connector, with high impact to confidentiality, integrity, and availability. An attacker can read sensitive identity and credential data, modify system configurations and managed account data, and disrupt service availability. Due to the scope change, the impact extends beyond the directly vulnerable component and may significantly affect other Oracle Fusion Middleware products integrated with Identity Manager Connector, increasing the risk of lateral movement within enterprise environments (Oracle Advisory, Feedly).

Mitigation and workarounds

Oracle has released a patch for CVE-2026-35294 as part of the June 2026 Critical Security Patch Update, available as of June 17, 2026. Affected versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Identity Manager Connector should be patched immediately by following the Fusion Middleware patch availability documentation referenced in the advisory (Oracle Advisory). As a temporary workaround prior to patching, Oracle recommends restricting network access to the Identity Manager Connector to trusted networks only and blocking HTTP access from untrusted sources. Oracle strongly advises against relying on network-level mitigations as a long-term solution, as they do not address the underlying vulnerability.

Community reactions

The vulnerability was noted in threat intelligence aggregators and security monitoring platforms shortly after Oracle's June 2026 CSPU release, with references appearing on VulDB and security radar services within hours of disclosure (Feedly). No significant independent researcher commentary or major media coverage specific to CVE-2026-35294 has been identified beyond standard vulnerability database entries and automated advisory republications.

Additional resources


SourceThis report was generated using AI

Related Oracle Identity Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61196CRITICAL9.8
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-61197CRITICAL9.1
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-60567CRITICAL9.1
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-60330HIGH8.5
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-60560HIGH8.1
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management