CVE-2026-46807
Oracle Identity Manager vulnerability analysis and mitigation

Overview

CVE-2026-46807 is a critical missing authentication vulnerability in the OIM Legacy UI component of Oracle Identity Manager, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0 and 14.1.2.1.0 and allows unauthenticated remote attackers to fully compromise the Identity Manager system via the T3 and IIOP protocols. The vulnerability was disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 9.8 (Critical) (Oracle Advisory).

Technical details

The vulnerability is classified as CWE-306 (Missing Authentication for Critical Function), meaning the OIM Legacy UI component exposes critical functionality over the T3 and IIOP protocols without requiring any authentication (Oracle Advisory). T3 is Oracle's proprietary protocol used by WebLogic Server for RMI-based communication, and IIOP (Internet Inter-ORB Protocol) is used for CORBA-based remote object access — both are commonly exposed on WebLogic-managed application servers. An attacker with network access to the affected ports can interact directly with the unprotected legacy UI component, requiring no credentials, no user interaction, and no special privileges. No public proof-of-concept exploit code has been identified at this time (Feedly).

Impact

Successful exploitation results in complete takeover of the Oracle Identity Manager system, with high impact to confidentiality, integrity, and availability. An attacker can read sensitive identity and access management data (including user credentials and provisioning configurations), modify system configurations and managed identities, and disrupt service availability. Because Oracle Identity Manager is a central identity governance platform, compromise could enable lateral movement across all systems and applications managed by OIM, including provisioning of unauthorized accounts (Oracle Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible Oracle Identity Manager instances running versions 12.2.1.4.0 or 14.1.2.1.0 using network scanning tools (e.g., Shodan, Censys, Nmap) targeting default WebLogic T3 (port 7001/7002) and IIOP (port 3700) ports.
  2. Protocol access: Establish a connection to the target using the T3 or IIOP protocol, which are exposed by the underlying WebLogic Server hosting the OIM Legacy UI component.
  3. Unauthenticated interaction: Interact with the OIM Legacy UI component directly over T3/IIOP without supplying any credentials, exploiting the missing authentication control (CWE-306) to access privileged functionality.
  4. System compromise: Leverage the unauthenticated access to read sensitive identity data, modify user accounts or provisioning configurations, deploy malicious payloads, or disrupt service availability — achieving full takeover of the Identity Manager system (Oracle Advisory, Feedly).

Indicators of compromise

  • Network: Unexpected inbound connections to WebLogic T3 ports (default 7001, 7002) or IIOP port (default 3700) from untrusted or external IP addresses; unusual volume of T3/IIOP connection attempts from a single source.
  • Logs: WebLogic server logs (server.log) showing unauthenticated T3 or IIOP sessions accessing OIM Legacy UI endpoints; access log entries for OIM Legacy UI resources without associated authenticated session tokens.
  • Process/Application: Unexpected changes to OIM user accounts, roles, or provisioning policies; new administrative accounts created without corresponding change management records.
  • File System: Unexpected files or scripts written to the WebLogic domain directory or OIM application directories by the application server process.

Mitigation and workarounds

Oracle has released patches for affected versions (12.2.1.4.0 and 14.1.2.1.0) as part of the June 2026 Critical Security Patch Update; customers should apply these patches immediately via the Fusion Middleware patch availability documentation (Oracle Advisory). As an interim workaround, restrict network access to T3 (ports 7001/7002) and IIOP (port 3700) on affected Identity Manager instances to trusted hosts only using firewall rules or network segmentation. Oracle strongly recommends against treating network-level blocking as a permanent solution, as it does not address the underlying vulnerability. Organizations should also monitor logs for suspicious T3/IIOP connection attempts and consider isolating affected systems until patching is complete (Feedly).

Community reactions

The vulnerability was noted in the broader context of Oracle's June 2026 CSPU, which addressed 245 security patches across multiple product families, drawing general attention to the scale of Oracle's patch release. Social media activity (including a Bluesky post from cyberhub.blog) referenced the vulnerability shortly after disclosure. No significant independent researcher commentary or detailed technical analysis has been publicly published as of the disclosure date (Feedly).

Additional resources


SourceThis report was generated using AI

Related Oracle Identity Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61196CRITICAL9.8
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-61197CRITICAL9.1
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-60567CRITICAL9.1
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-60330HIGH8.5
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-60560HIGH8.1
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management