
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-60330 is a vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware, specifically affecting the OIM Legacy UI component. It affects supported versions 12.2.1.4.0 and 14.1.2.1.0. A low-privileged attacker with network access via HTTP can exploit this difficult-to-exploit vulnerability to fully compromise Oracle Identity Manager, with attacks potentially impacting additional products (scope change). It carries a CVSS v3.1 base score of 8.5 (High) (Oracle CPU Jul 2026).
The vulnerability resides in the OIM Legacy UI component of Oracle Identity Manager and is exploitable over HTTP by a low-privileged, authenticated attacker without requiring user interaction. The attack complexity is rated High, indicating that specific conditions or configurations must be met for successful exploitation. The changed scope indicates that a successful attack can affect resources beyond the vulnerable component itself. No specific CWE classification or detailed technical write-up has been publicly disclosed by Oracle at this time (Oracle CPU Jul 2026).
Successful exploitation can result in a full takeover of Oracle Identity Manager, with high impacts to confidentiality, integrity, and availability. Because Oracle Identity Manager is an identity governance platform managing user provisioning and access across enterprise systems, a compromise could enable unauthorized access to connected applications and directories, facilitating lateral movement across the environment. The changed scope further indicates that additional products integrated with Oracle Identity Manager may also be affected (Oracle CPU Jul 2026).
Oracle has addressed this vulnerability as part of the July 2026 Critical Patch Update (CPU). Customers running Oracle Identity Manager versions 12.2.1.4.0 or 14.1.2.1.0 should apply the relevant patches from the July 2026 CPU immediately. Oracle strongly recommends applying patches as soon as possible and advises against relying on network-blocking workarounds as a long-term solution. Until patches are applied, restricting HTTP network access to Oracle Identity Manager from untrusted or low-privileged users may reduce risk (Oracle CPU Jul 2026).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."