CVE-2026-46792: Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector)
Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager Connector. While the vulnerability is in Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Identity Manager Connector. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 9.9
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
This is a critical-severity vulnerability affecting Oracle Identity Manager Connector (Generic Unix Connector component), versions 12.2.1.4.0 and 14.1.2.1.0. An attacker with a low-privilege account and HTTP network access can exploit this flaw without any victim interaction, achieving full takeover of the connector service including confidentiality, integrity, and availability impacts that extend beyond the connector itself to additional products in the environment (a CVSS scope change). No upstream fix version has been published as of the CVE record date; HarborGuard is tracking the advisory for patch availability.
HarborGuard Coverage
Detection for CVE-2026-46792 is available across every HarborGuard environment: the CVE is ingested from upstream Oracle and NVD feeds within minutes of publication and matched against customer images, including custom-built images that package the affected connector component. Any image running Identity Manager Connector versions 12.2.1.4.0 or 14.1.2.1.0 is flagged automatically in CI pipelines and registry scans.
AvailableHarborGuard surfaces CVE-2026-46792 with its CVSS v3.1 base score of 9.9 (Critical) and applies per-environment compliance policy weighting to determine breach-of-policy status. Triage notifications are routed to the team inbox configured for each customer organization, enabling rapid prioritization without manual score lookups.
AvailableBecause no upstream fix version has been published, HarborGuard re-evaluates the advisory on every ingest cycle and will make a patched-image rebuild available the moment Oracle ships a correcting release. In the interim, customers can apply network-policy controls and egress filtering through HarborGuard compensating-control recommendations to reduce exposure while the vulnerability is unpatched.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the Identity Manager Connector service over the network via HTTP; there is no local or physical access requirement.
- AuthenticationRequired
A low-privilege account is sufficient; any valid authenticated user on the network can initiate the attack, but unauthenticated access alone does not trigger the flaw.
- Victim interactionNot required
No user action or social-engineering step is needed; the attacker operates entirely on their own without involving a victim.
- Attack complexityDetail
Attack complexity is Low, meaning the exploit is reliable and requires no special race conditions, memory layout knowledge, or other environmental factors to succeed.
Blast Radius
- A successful attacker gains full read access to all data handled by the connector, including stored credentials, Unix account mappings, and identity provisioning records.
- The attacker can modify or delete provisioned Unix account configurations and identity data persisted by the connector, corrupting downstream provisioning workflows.
- The connector service can be crashed or made permanently unavailable, halting identity provisioning operations that depend on it.
- Because the CVSS scope change applies, the impact propagates to additional Oracle Fusion Middleware products sharing the environment, expanding attacker reach beyond the connector itself.
How HarborGuard Handles This
Available on HarborGuard: because no Oracle-published fix version exists for CVE-2026-46792 at this time, the platform monitors the Oracle and NVD advisory feeds on every ingest cycle and will automatically make a patched-image rebuild available the moment an upstream fix is released. For customers with auto-remediation enabled, that rebuild will trigger a regression test run and a PR opened against affected workloads without manual intervention. While the vulnerability is unpatched, HarborGuard recommends applying network-policy isolation to restrict HTTP access to the Generic Unix Connector to only authorized provisioning systems, enabling egress filtering to limit lateral movement in the event of compromise, and reviewing feature-flag or connector-disablement options for environments where Unix Connector functionality is not actively required. All of these compensating controls can be tracked as policy exceptions within HarborGuard until the upstream patch is available.
- Oracle Corporation / Identity Manager Connector12.2.1.4.0 · 14.1.2.1.0
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H