PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60534 Oracle CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:53.170Z and has not been modified since then. The vulnerability is in Oracle Identity Manager Connector, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It has a CVSS 3.1 Base Score of 7.7, indicating high severity. The vulnerability allows high privileged attackers with network access via HTTP to compromise Oracle Identity Manager Connector, potentially impacting additional products and allowing unauthorized data access or modification. Organizations should review the CVE record and NVD detail page for further guidance and take immediate action to mitigate potential risks. Defenders should verify the presence of these versions in their environments and assess potential impact. Evidence from the CVE record and NVD detail page supports this assessment. Additional information from vendor advisories may be necessary for comprehensive risk evaluation.

Vendor
Oracle
Product
Identity Manager Connector
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-28
Advisory published
2026-07-21
Advisory updated
2026-07-28

Who should care

Organizations using Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0 should prioritize patching and monitoring. Security teams and vulnerability management teams should assess the risk and implement necessary controls. Operators of affected systems should review the CVE record and NVD detail page for further guidance. Platform administrators and security personnel responsible for Oracle Identity Manager Connector deployments should take immediate action to mitigate potential risks.

Technical summary

The vulnerability is in Oracle Identity Manager Connector, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It has a CVSS 3.1 Base Score of 7.7, indicating high severity. The vulnerability allows high privileged attackers with network access via HTTP to compromise Oracle Identity Manager Connector, potentially impacting additional products and allowing unauthorized data access or modification. The technical impact includes potential unauthorized creation, deletion, or modification access to critical data or all Oracle Identity Manager Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data.

Defensive priority

High privileged attackers with network access via HTTP could compromise Oracle Identity Manager Connector, potentially impacting additional products and allowing unauthorized data access or modification.

Recommended defensive actions

  • Inventory Oracle Identity Manager Connector instances for versions 12.2.1.4.0 and 14.1.2.1.0
  • Apply vendor patches or updates as available
  • Monitor for suspicious network activity via HTTP
  • Restrict access to critical data and systems
  • Implement compensating controls for high privileged attackers
  • Review and update asset inventory to ensure accurate tracking of affected systems
  • Conduct regular security audits to identify potential vulnerabilities

Evidence notes

The vulnerability is in Oracle Identity Manager Connector, affecting versions 12.2.1.4.0 and 14.1.2.1.0. CVSS 3.1 Base Score is 7.7, indicating high severity. The NVD entry is currently Analyzed. Defenders should verify the presence of these versions in their environments and assess potential impact. Evidence from the CVE record and NVD detail page supports this assessment. Additional information from vendor advisories may be necessary for comprehensive risk evaluation.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:53.170Z and has not been modified since then.