
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-61066 is an Improper Access Control vulnerability (CWE-284) in the OIM Legacy UI component of Oracle Identity Manager, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability was published on August 18, 2026, and addressed in Oracle's August 2026 Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 9.9 (Critical), reflecting its network-accessible, low-complexity, low-privilege attack vector with a changed scope (Oracle CSPU Aug 2026, Feedly).
The vulnerability is classified as Improper Access Control (CWE-284) within the OIM Legacy UI component of Oracle Identity Manager. Exploitation occurs over the RMI (Remote Method Invocation) protocol, requiring only low-level network privileges — no user interaction is needed and attack complexity is low. The scope is marked as "Changed," indicating that a successful attack can extend beyond Oracle Identity Manager itself to impact additional connected products or systems. No detailed public technical write-ups or proof-of-concept code have been identified at this time (Oracle CSPU Aug 2026, Feedly).
Successful exploitation allows a low-privileged remote attacker to achieve complete takeover of Oracle Identity Manager, with high impact to confidentiality, integrity, and availability. Because Oracle Identity Manager is a centralized identity and access management platform, compromise can expose sensitive user credentials, role assignments, and provisioning data across all connected enterprise systems. The changed scope means attacks may propagate to additional integrated products, significantly amplifying the blast radius beyond the initial target (Oracle CSPU Aug 2026, Feedly).
As of the time of publication, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.36%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. NVD's SSVC assessment classifies exploitation as "none" and automation as "no," suggesting that while the vulnerability is severe, active weaponization has not yet been observed (Feedly).
Oracle has released a patch for CVE-2026-61066 as part of the August 2026 Critical Security Patch Update (CSPU), and organizations should apply it immediately for affected versions 12.2.1.4.0 and 14.1.2.1.0. As a temporary workaround prior to patching, Oracle recommends restricting network access to the RMI port used by Oracle Identity Manager to only authorized administrators and systems. Additionally, organizations should review and minimize the number of low-privileged accounts with network access to OIM, and monitor RMI traffic for suspicious activity. Oracle strongly advises against relying on network-level controls as a long-term solution (Oracle CSPU Aug 2026).
The vulnerability was noted on Bluesky by security community accounts shortly after disclosure, and it appeared in Rapid7's vulnerability database listing. No major vendor statements beyond Oracle's advisory or significant researcher commentary have been identified at this time (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."