PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60994 Oracle Corporation CVE debrief

CVE-2026-60994 is a high-severity vulnerability in Oracle Identity Manager Connector, a component of Oracle Fusion Middleware. The vulnerability, classified under the Core component, affects versions 12.2.1.4.0 and 14.1.2.1.0. It is a difficult-to-exploit vulnerability that requires low privileges and human interaction to compromise the Oracle Identity Manager Connector. Successful exploitation could lead to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. The CVSS 3.1 Base Score is 7.2, indicating high severity for both confidentiality and integrity impacts. The vulnerability's scope can change, potentially impacting additional products beyond Oracle Identity Manager Connector. Organizations using the affected versions should prioritize patching due to the high CVSS score and potential for significant impact. The CVE record was published on 2026-08-18T21:16:51.030Z and has not been modified since then.

Vendor
Oracle Corporation
Product
Oracle Identity Manager Connector
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-08-21
Advisory published
2026-08-18
Advisory updated
2026-08-21

Who should care

Organizations using Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0 should prioritize patching due to the high CVSS score of 7.2 and potential for significant impact. Security teams, vulnerability management teams, and operators responsible for Oracle Identity Manager Connector infrastructure should be aware of this vulnerability and take necessary actions to mitigate the risk. Additionally, platform administrators and security auditors should review the affected systems and ensure that compensating controls are in place while remediation is scheduled and verified.

Technical summary

CVE-2026-60994 is a high-severity vulnerability in Oracle Identity Manager Connector, with a CVSS score of 7.2. It requires low privileges and human interaction to exploit, potentially impacting confidentiality and integrity of critical data. The vulnerability affects Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0. Successful exploitation could lead to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. The vulnerability's scope can change, potentially impacting additional products beyond Oracle Identity Manager Connector. Organizations should prioritize patching due to the high CVSS score and potential for significant impact.

Defensive priority

Organizations using Oracle Identity Manager Connector 12.2.1.4.0 and 14.1.2.1.0 should prioritize patching due to the high CVSS score of 7.2 and potential for significant impact.

Recommended defensive actions

  • Apply patches for Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0
  • Restrict access to Oracle Identity Manager Connector infrastructure
  • Monitor for suspicious activity
  • Implement compensating controls for critical data access
  • Review and update asset inventory to identify exposed systems
  • Track exceptions and retest remediated assets
  • Plan for regular security audits and vulnerability assessments

Evidence notes

The CVE-2026-60994 vulnerability in Oracle Identity Manager Connector has a CVSS score of 7.2, indicating high severity. It requires human interaction and low privileges to exploit, potentially impacting additional products. The evidence provided is based on the official CVE record and NVD details. However, further verification is recommended to ensure that the vulnerability does not have a broader impact than described. Defenders should verify the affected versions (12.2.1.4.0 and 14.1.2.1.0) and assess their exposure. The vulnerability's scope change potential means that attacks could significantly impact other products beyond Oracle Identity Manager Connector. Additional review of related systems and compensating controls may be necessary.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:51.030Z and has not been modified since then.