CVE-2026-21992Missing Authentication for Critical Function in Corporation Oracle Identity Manager

Severity
9.8CRITICALNVD
EPSS
0.1%
top 81.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 20
Latest updateMar 21

Description

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager and Oracle Web Services Manager. Successful attacks of this vulnerability can result

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

NVDoracle/web_services_manager12.2.1.4.0, 14.1.2.1.0+1
CVEListV5oracle_corporation/oracle_web_services_manager12.2.1.4.0, 14.1.2.1.0+1
NVDoracle/identity_manager12.2.1.4.0, 14.1.2.1.0+1
CVEListV5oracle_corporation/oracle_identity_manager12.2.1.4.0, 14.1.2.1.0+1

🔴Vulnerability Details

2
CVEList
CVE-2026-21992: Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product2026-03-20
GHSA
GHSA-hg4m-m77p-qp8j: Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product2026-03-20

🕵️Threat Intelligence

3
Hackernews
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager2026-03-21
Bleepingcomputer
Oracle pushes emergency fix for critical Identity Manager RCE flaw2026-03-20
Wiz
CVE-2026-21992 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-21992 — CRITICAL severity | cvebase