Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60994

CVE-2026-60994: Oracle Identity Manager Privilege Escalation

CVE-2026-60994 is a privilege escalation vulnerability in Oracle Identity Manager Connector affecting versions 12.2.1.4.0 and 14.1.2.1.0. This flaw enables unauthorized data access and modification. Explore technical details, impact, and fixes.

Published:

CVE-2026-60994 Overview

CVE-2026-60994 is a high-severity vulnerability in the Oracle Identity Manager Connector, a component of Oracle Fusion Middleware. The flaw affects supported versions 12.2.1.4.0 and 14.1.2.1.0. A low-privileged attacker with local logon access to the infrastructure running the connector can compromise the product when a separate user performs a required interaction. The vulnerability carries scope change, so successful exploitation can affect additional products beyond the connector itself. Impact includes unauthorized creation, deletion, or modification of critical data and unauthorized read access to all connector-accessible data.

Critical Impact

Successful exploitation grants unauthorized read and write access to all data accessible by Oracle Identity Manager Connector, with scope change that may impact adjacent Oracle Fusion Middleware components.

Affected Products

  • Oracle Identity Manager Connector 12.2.1.4.0
  • Oracle Identity Manager Connector 14.1.2.1.0
  • Oracle Fusion Middleware (Core component)

Discovery Timeline

  • 2026-08-18 - CVE-2026-60994 published to the National Vulnerability Database
  • 2026-08-20 - Last updated in NVD database

Technical Details for CVE-2026-60994

Vulnerability Analysis

The vulnerability resides in the Core component of the Oracle Identity Manager Connector, which brokers identity provisioning between Oracle Identity Manager and downstream target systems. Exploitation requires the attacker to already hold low-privileged access to the infrastructure where the connector executes, and to induce a separate user to perform an action. The scope change indicates the vulnerable component and the impacted component are governed by different security authorities. This is characteristic of identity brokers, where compromised connector logic can be used to manipulate credentials, entitlements, or provisioning data for downstream systems. The confidentiality and integrity impacts are both rated High, while availability is unaffected.

Root Cause

Oracle has not published the underlying weakness class or code-level detail for CVE-2026-60994. Based on the CVSS attack vector, the flaw is reachable only from the local infrastructure hosting the connector and requires authenticated access plus user interaction. The scope change strongly suggests a trust boundary crossing between the connector process and adjacent identity or middleware components.

Attack Vector

An authenticated local attacker with a low-privilege account on the host running Oracle Identity Manager Connector triggers the vulnerable code path. A second user must interact with attacker-supplied content or workflow input for the attack to succeed. Once triggered, the attacker gains full read and modification capability across data reachable by the connector, and the impact crosses security scopes into other products in the Oracle Fusion Middleware stack.

No public proof-of-concept code is available. Oracle has not released technical exploitation detail. Refer to the Oracle Security Alert for authoritative guidance.

Detection Methods for CVE-2026-60994

Indicators of Compromise

  • Unexpected provisioning, deprovisioning, or role changes originating from the Oracle Identity Manager Connector service account
  • New or modified connector configuration files, JAR files, or scheduled tasks on hosts running versions 12.2.1.4.0 or 14.1.2.1.0
  • Anomalous cross-scope actions where the connector interacts with Fusion Middleware components outside its normal workflow

Detection Strategies

  • Enable and forward Oracle Identity Manager audit logs, WebLogic server logs, and OS-level process and file integrity events to a centralized analytics platform
  • Baseline the identities, hosts, and destinations that the connector normally contacts, then alert on deviations
  • Correlate local logon events on connector hosts with subsequent identity provisioning activity to catch abuse chains that require the low-privilege plus user-interaction pattern described in the CVSS vector

Monitoring Recommendations

  • Monitor authentication and privilege changes made by the connector service account against Active Directory, Entra ID, and other downstream targets
  • Track file changes under Oracle Identity Manager Connector installation directories and any custom adapter code
  • Review scheduled reconciliation jobs and connector task definitions for unauthorized modifications

How to Mitigate CVE-2026-60994

Immediate Actions Required

  • Apply the patches referenced in the Oracle Security Alert for 12.2.1.4.0 and 14.1.2.1.0 at the next available maintenance window
  • Restrict local logon on servers hosting Oracle Identity Manager Connector to a minimal set of administrators
  • Remove interactive session capability from any account that only needs service-level access to the connector host

Patch Information

Oracle addressed CVE-2026-60994 in the August 2026 Critical Patch Update. Administrators should download and apply the fixes documented in the Oracle Security Alert for each affected supported version. Oracle does not backport fixes to unsupported releases, so environments on out-of-support versions must upgrade.

Workarounds

  • Enforce least privilege for all accounts with local access to connector hosts, and require multi-factor authentication for administrative sessions
  • Segment connector infrastructure from general-purpose workloads to reduce the population of users who can satisfy the local attack vector
  • Require change control and peer review for any user-supplied artifacts, scripts, or configuration handled by connector operators, mitigating the required user-interaction step

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.