
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-46807 is a critical missing authentication vulnerability in the OIM Legacy UI component of Oracle Identity Manager, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0 and 14.1.2.1.0 and allows unauthenticated remote attackers to fully compromise the Identity Manager system via the T3 and IIOP protocols. The vulnerability was disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 9.8 (Critical) (Oracle Advisory).
The vulnerability is classified as CWE-306 (Missing Authentication for Critical Function), meaning the OIM Legacy UI component exposes critical functionality over the T3 and IIOP protocols without requiring any authentication (Oracle Advisory). T3 is Oracle's proprietary protocol used by WebLogic Server for RMI-based communication, and IIOP (Internet Inter-ORB Protocol) is used for CORBA-based remote object access — both are commonly exposed on WebLogic-managed application servers. An attacker with network access to the affected ports can interact directly with the unprotected legacy UI component, requiring no credentials, no user interaction, and no special privileges. No public proof-of-concept exploit code has been identified at this time (Feedly).
Successful exploitation results in complete takeover of the Oracle Identity Manager system, with high impact to confidentiality, integrity, and availability. An attacker can read sensitive identity and access management data (including user credentials and provisioning configurations), modify system configurations and managed identities, and disrupt service availability. Because Oracle Identity Manager is a central identity governance platform, compromise could enable lateral movement across all systems and applications managed by OIM, including provisioning of unauthorized accounts (Oracle Advisory, Feedly).
server.log) showing unauthenticated T3 or IIOP sessions accessing OIM Legacy UI endpoints; access log entries for OIM Legacy UI resources without associated authenticated session tokens.Oracle has released patches for affected versions (12.2.1.4.0 and 14.1.2.1.0) as part of the June 2026 Critical Security Patch Update; customers should apply these patches immediately via the Fusion Middleware patch availability documentation (Oracle Advisory). As an interim workaround, restrict network access to T3 (ports 7001/7002) and IIOP (port 3700) on affected Identity Manager instances to trusted hosts only using firewall rules or network segmentation. Oracle strongly recommends against treating network-level blocking as a permanent solution, as it does not address the underlying vulnerability. Organizations should also monitor logs for suspicious T3/IIOP connection attempts and consider isolating affected systems until patching is complete (Feedly).
The vulnerability was noted in the broader context of Oracle's June 2026 CSPU, which addressed 245 security patches across multiple product families, drawing general attention to the scale of Oracle's patch release. Social media activity (including a Bluesky post from cyberhub.blog) referenced the vulnerability shortly after disclosure. No significant independent researcher commentary or detailed technical analysis has been publicly published as of the disclosure date (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."