HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-46793Published Modified CNA oracle

CVE-2026-46793: Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Database User)

Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Database User). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager Connector. While the vulnerability is in Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Identity Manager Connector. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Metrics

CVSS v3.1
9.9
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A critical-severity vulnerability in Oracle Identity Manager Connector (versions 12.2.1.4.0 and 14.1.2.1.0, Database User component) allows any authenticated low-privilege user to send a crafted HTTP request over the network and fully compromise the service. The CVSS scope is marked as changed, meaning a successful attack can spill into adjacent systems beyond Identity Manager Connector itself. Successful exploitation gives the attacker full read, write, and availability control over Identity Manager Connector and potentially other products in the environment. No vendor fix has been published yet; HarborGuard is tracking the advisory and will surface patch availability as soon as Oracle ships a fix.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle Oracle Fusion Middleware components.

Available
Triage

HarborGuard scores this finding at CVSS 9.9 Critical and weights it further against each environment's compliance policy, routing alerts to the appropriate team inbox based on asset criticality and policy rules configured by the customer org.

Available
Patch

Because no vendor fix version has been published for this CVE, HarborGuard re-evaluates the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment Oracle publishes a fix. In the meantime, customers can apply compensating controls through HarborGuard's network-policy isolation recommendations to limit exposure until a patch is available.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the Identity Manager Connector service over the network via HTTP; this is an over-the-network exposure with no physical access requirement.

  • AuthenticationRequired

    Any low-privilege account is sufficient; the attacker does not need administrative credentials, but some valid account is required.

  • Victim interactionNot required

    No user action or social engineering is needed; the attacker can exploit this entirely on their own.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and requires no special race conditions, memory-layout knowledge, or other environmental prerequisites.

Blast Radius

  • Reads all data managed by Identity Manager Connector, including stored user credentials, identity records, and connector configuration secrets.
  • Modifies or deletes identity and database-user provisioning records, enabling privilege escalation or unauthorized account creation across connected systems.
  • Crashes or degrades the Identity Manager Connector service, disrupting identity provisioning workflows for any system that depends on it.
  • Because the CVSS scope is changed, a successful attacker can pivot to additional Oracle Fusion Middleware products or other systems that trust Identity Manager Connector.

How HarborGuard Handles This

Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-46793, the platform monitors the advisory on every ingest cycle and will trigger a patched-image rebuild automatically as soon as an upstream fix version is released. For customers with auto-remediation enabled, that rebuild is followed by a regression-test run and a PR opened against affected workloads with no manual steps required. While no patch is available, HarborGuard can surface compensating-control recommendations including network-policy rules to restrict HTTP access to Identity Manager Connector endpoints, egress filtering to limit lateral movement in the event of compromise, and feature-flag gating to disable the Database User component where it is not operationally required. Where compliance policy permits, HarborGuard will open a triage ticket and route it to the appropriate team inbox immediately, given the Critical severity and scope-change designation of this CVE.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Identity Manager Connector
    12.2.1.4.0 · 14.1.2.1.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
References