
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35294 is an Improper Access Control vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware, specifically in the Mainframe Connectors component. It affects versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Identity Manager Connector. The vulnerability was disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 9.9 (Critical), reflecting its network-accessible, low-complexity attack vector with scope change (Oracle Advisory, Feedly).
The vulnerability is classified as CWE-284 (Improper Access Control), indicating that the Mainframe Connectors component of Oracle Identity Manager Connector fails to properly enforce access restrictions on HTTP-accessible functionality (Feedly). A low-privileged attacker with network access via HTTP can exploit this flaw without requiring user interaction or elevated privileges, making it easily exploitable. The vulnerability has a changed scope, meaning successful exploitation can extend impact beyond the Identity Manager Connector itself to affect additional products within the Oracle Fusion Middleware ecosystem (Oracle Advisory). No public proof-of-concept or detailed technical write-up has been published as of the disclosure date.
Successful exploitation results in a complete takeover of the Identity Manager Connector, with high impact to confidentiality, integrity, and availability. An attacker can read sensitive identity and credential data, modify system configurations and managed account data, and disrupt service availability. Due to the scope change, the impact extends beyond the directly vulnerable component and may significantly affect other Oracle Fusion Middleware products integrated with Identity Manager Connector, increasing the risk of lateral movement within enterprise environments (Oracle Advisory, Feedly).
Oracle has released a patch for CVE-2026-35294 as part of the June 2026 Critical Security Patch Update, available as of June 17, 2026. Affected versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Identity Manager Connector should be patched immediately by following the Fusion Middleware patch availability documentation referenced in the advisory (Oracle Advisory). As a temporary workaround prior to patching, Oracle recommends restricting network access to the Identity Manager Connector to trusted networks only and blocking HTTP access from untrusted sources. Oracle strongly advises against relying on network-level mitigations as a long-term solution, as they do not address the underlying vulnerability.
The vulnerability was noted in threat intelligence aggregators and security monitoring platforms shortly after Oracle's June 2026 CSPU release, with references appearing on VulDB and security radar services within hours of disclosure (Feedly). No significant independent researcher commentary or major media coverage specific to CVE-2026-35294 has been identified beyond standard vulnerability database entries and automated advisory republications.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."