CVE-2026-46810
Oracle Identity Manager vulnerability analysis and mitigation

Overview

CVE-2026-46810 is an improper access control vulnerability in the End User Self Service component of Oracle Identity Manager, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability allows unauthenticated attackers with network access via the IIOP protocol to perform unauthorized read, insert, update, or delete operations on a subset of Identity Manager accessible data. It was disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update, with a CVSS v3.1 base score of 6.5 (Medium) (Oracle Advisory, NVD).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control), meaning the affected component fails to properly restrict access to Identity Manager data over the IIOP (Internet Inter-ORB Protocol) network interface (NVD). An unauthenticated remote attacker can exploit this flaw by sending crafted IIOP requests to the End User Self Service component without requiring any credentials or user interaction. The attack complexity is low and the vulnerability is considered automatable by CISA-ADP, meaning exploitation can be scripted or repeated at scale (Oracle Advisory). No public technical write-ups or proof-of-concept code have been identified at this time.

Impact

Successful exploitation allows an unauthenticated attacker to read a subset of Identity Manager accessible data (confidentiality impact) and perform unauthorized update, insert, or delete operations on some Identity Manager data (integrity impact). Availability is not impacted. Because Oracle Identity Manager is a centralized identity governance platform, unauthorized data manipulation could affect user provisioning, access rights, and role assignments across connected enterprise systems, potentially enabling privilege escalation or unauthorized access to downstream resources (Oracle Advisory, NVD).

Mitigation and workarounds

Oracle has released patches for affected versions (12.2.1.4.0 and 14.1.2.1.0) as part of the June 2026 Critical Security Patch Update; customers should apply these patches immediately (Oracle Advisory). As a temporary workaround, organizations should restrict network access to the IIOP protocol interface (typically TCP port 3700) to trusted hosts only, using firewalls or network ACLs. Oracle strongly recommends against relying on network-level mitigations as a long-term solution, as they do not address the underlying vulnerability. Organizations should also monitor Identity Manager audit logs for unexpected data modification activities such as unauthorized inserts, updates, or deletes.

Additional resources


SourceThis report was generated using AI

Related Oracle Identity Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61196CRITICAL9.8
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-61197CRITICAL9.1
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-60567CRITICAL9.1
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-60330HIGH8.5
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026
CVE-2026-60560HIGH8.1
  • Oracle Identity Manager logoOracle Identity Manager
  • cpe:2.3:a:oracle:identity_manager
NoNoJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management