CVE-2026-46807: Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI)
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 9.8
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
This is a critical-severity unauthenticated remote code execution vulnerability in Oracle Identity Manager (OIM Legacy UI), affecting versions 12.2.1.4.0 and 14.1.2.1.0. An attacker with network access to the T3 or IIOP protocol ports can reach the vulnerable component without any credentials or user interaction. Successful exploitation results in full takeover of the Identity Manager instance, including complete compromise of confidentiality, integrity, and availability. No fix version has been published by Oracle; HarborGuard is tracking the advisory and will make a patched-image rebuild available as soon as upstream ships a fix.
HarborGuard Coverage
Detection for CVE-2026-46807 is available across every HarborGuard environment: the CVE is ingested from upstream advisory feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Oracle Identity Manager components. Any image carrying the affected versions (12.2.1.4.0 or 14.1.2.1.0) will surface in the affected-image list for the owning team.
AvailableTriage is available with a CVSS 3.1 score of 9.8 (Critical), surfaced alongside per-environment compliance policy weighting so teams with stricter SLAs see this issue escalated automatically. Routing to the appropriate inbox within each customer organization is handled according to that organization's configured ownership and severity-threshold rules.
AvailableNo fix version has been published by Oracle for this CVE. HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available the moment Oracle publishes a corrected version. For customers who opt into auto-remediation, the rebuild, regression-test run, and PR against affected workloads will be triggered automatically at that point, subject to each organization's compliance policy.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the target service over the network via the T3 or IIOP protocol ports exposed by the Identity Manager deployment.
- AuthenticationNot required
No credentials of any kind are required; the vulnerable endpoint is reachable by any unauthenticated network client.
- Victim interactionNot required
No user action or social engineering is needed; the attacker drives the exploit entirely from the network.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and requires no race conditions, special memory layout, or environmental preconditions beyond network access.
Blast Radius
- A successful attacker gains full control of the Identity Manager process, including the ability to read all identity data, credentials, and provisioning records managed by the system.
- The attacker can modify or delete user accounts, roles, entitlements, and provisioning workflows stored in Identity Manager.
- The attacker can crash or render the Identity Manager service completely unavailable, disrupting identity provisioning and authentication workflows across connected systems.
- Because Identity Manager typically federates into downstream enterprise directories and applications, a takeover can serve as a pivot point to compromise connected systems that trust its provisioning decisions.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-46807 is active for any image containing Oracle Identity Manager 12.2.1.4.0 or 14.1.2.1.0. Because Oracle has not yet published a fix, no patched-image rebuild is available at this time. HarborGuard re-checks the Oracle advisory on every ingest cycle; once a fix version is released, a patched rebuild will become available automatically, and customers with auto-remediation enabled will receive the rebuild, a regression-test run, and a PR opened against affected workloads (where compliance policy permits). In the interim, recommended compensating controls include isolating the T3 and IIOP ports (typically 7001, 7002, and configured IIOP ports) behind strict network policy so only authorized internal systems can reach them, applying egress filtering to limit lateral movement from a compromised instance, and auditing Identity Manager's connected downstream directories for anomalous provisioning activity. Teams should treat this as a critical-priority issue given the zero-authentication, full-takeover impact profile.
- Oracle Corporation / Identity Manager12.2.1.4.0 · 14.1.2.1.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H