Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60330

CVE-2026-60330: Oracle Identity Manager Privilege Escalation

CVE-2026-60330 is a privilege escalation vulnerability in Oracle Identity Manager that allows low privileged attackers to compromise the system. This article covers the technical details, affected versions, and mitigation steps.

Published:

CVE-2026-60330 Overview

CVE-2026-60330 is a vulnerability in the Oracle Identity Manager (OIM) product of Oracle Fusion Middleware, specifically in the OIM Legacy UI component. The flaw affects supported versions 12.2.1.4.0 and 14.1.2.1.0. A low-privileged attacker with network access via HTTP can exploit the issue, though successful exploitation is difficult. The vulnerability carries a scope change, meaning attacks may affect components beyond Oracle Identity Manager itself. Successful exploitation results in complete takeover of Oracle Identity Manager, impacting confidentiality, integrity, and availability.

Critical Impact

Successful exploitation allows a low-privileged authenticated attacker to take over Oracle Identity Manager and impact additional products through scope change.

Affected Products

  • Oracle Identity Manager 12.2.1.4.0
  • Oracle Identity Manager 14.1.2.1.0
  • Oracle Fusion Middleware (OIM Legacy UI component)

Discovery Timeline

  • 2026-07-21 - CVE-2026-60330 published to NVD
  • 2026-07-23 - Last updated in NVD database
  • July 2026 - Addressed in Oracle Critical Patch Update via the Oracle Security Advisory July 2026

Technical Details for CVE-2026-60330

Vulnerability Analysis

The vulnerability resides in the OIM Legacy UI component of Oracle Identity Manager, a core identity governance product within Oracle Fusion Middleware. An authenticated attacker with low privileges can send crafted HTTP requests to trigger the flaw. Exploitation requires no user interaction but is rated as high complexity, indicating specific preconditions must be met. Because the scope changes upon exploitation, the attacker can reach resources beyond the vulnerable component's security authority. This makes lateral movement into downstream applications trusted by OIM feasible.

Oracle Identity Manager brokers authentication, provisioning, and access decisions for enterprise applications. A compromise of OIM enables an attacker to manipulate identity data, create privileged accounts, and forge access grants across integrated systems.

Root Cause

Oracle has not published detailed root-cause information for this flaw. The advisory categorizes it under the OIM Legacy UI, which suggests a defect in the legacy web interface's request handling or trust boundary. Refer to the Oracle Security Advisory July 2026 for vendor-supplied details.

Attack Vector

The attack originates over the network using HTTP against the OIM Legacy UI. The attacker must hold low-level credentials on the target OIM instance before exploitation. No user interaction is required. Successful attacks yield full takeover of Oracle Identity Manager and can propagate to additional products because of the scope change.

No public proof-of-concept code or exploit is available for CVE-2026-60330. The EPSS score is 0.345% (percentile 26.978), indicating low near-term exploitation probability as of 2026-07-23.

Detection Methods for CVE-2026-60330

Indicators of Compromise

  • Unexpected administrative account creation or role assignments performed through the OIM Legacy UI.
  • Anomalous HTTP requests targeting legacy OIM endpoints from low-privileged user sessions.
  • Provisioning or entitlement changes originating from sessions that do not correspond to normal help-desk or admin workflows.

Detection Strategies

  • Enable and centralize Oracle Identity Manager audit logs, focusing on the Legacy UI request paths and privileged operations.
  • Correlate authentication events with subsequent administrative actions to identify low-privileged accounts performing scope-changing operations.
  • Baseline normal HTTP request patterns to OIM Legacy UI endpoints and alert on deviations, especially requests producing role or entitlement modifications.

Monitoring Recommendations

  • Forward OIM application logs, WebLogic server logs, and reverse-proxy logs to a centralized analytics platform for retention and query.
  • Monitor downstream systems integrated with OIM for unexpected provisioning events that could indicate a scope-change exploit chain.
  • Alert on privilege changes affecting service accounts and administrator roles managed by OIM.

How to Mitigate CVE-2026-60330

Immediate Actions Required

  • Apply the July 2026 Oracle Critical Patch Update to Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 as soon as change control permits.
  • Inventory all OIM deployments and confirm which instances expose the Legacy UI component.
  • Review recent OIM audit logs for suspicious low-privileged account activity predating the patch.
  • Rotate credentials for any accounts that could have been used to authenticate to the Legacy UI if compromise is suspected.

Patch Information

Oracle addressed CVE-2026-60330 in the July 2026 Critical Patch Update. Consult the Oracle Security Advisory July 2026 for the specific patch bundle applicable to your OIM version and deployment topology.

Workarounds

  • Restrict network access to the OIM Legacy UI to trusted administrative networks via firewall or reverse-proxy access control lists.
  • Disable or decommission the Legacy UI component if it is not required for operational workflows.
  • Enforce least-privilege principles on OIM accounts to reduce the pool of users who satisfy the low-privilege precondition.
  • Require multi-factor authentication for all OIM accounts to raise the cost of credential-based access.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.