PatchSiren cyber security CVE debrief
CVE-2026-60534 Oracle CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:53.170Z and has not been modified since then. The vulnerability is in Oracle Identity Manager Connector, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It has a CVSS 3.1 Base Score of 7.7, indicating high severity. The vulnerability allows high privileged attackers with network access via HTTP to compromise Oracle Identity Manager Connector, potentially impacting additional products and allowing unauthorized data access or modification. Organizations should review the CVE record and NVD detail page for further guidance and take immediate action to mitigate potential risks. Defenders should verify the presence of these versions in their environments and assess potential impact. Evidence from the CVE record and NVD detail page supports this assessment. Additional information from vendor advisories may be necessary for comprehensive risk evaluation.
- Vendor
- Oracle
- Product
- Identity Manager Connector
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-28
Who should care
Organizations using Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0 should prioritize patching and monitoring. Security teams and vulnerability management teams should assess the risk and implement necessary controls. Operators of affected systems should review the CVE record and NVD detail page for further guidance. Platform administrators and security personnel responsible for Oracle Identity Manager Connector deployments should take immediate action to mitigate potential risks.
Technical summary
The vulnerability is in Oracle Identity Manager Connector, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It has a CVSS 3.1 Base Score of 7.7, indicating high severity. The vulnerability allows high privileged attackers with network access via HTTP to compromise Oracle Identity Manager Connector, potentially impacting additional products and allowing unauthorized data access or modification. The technical impact includes potential unauthorized creation, deletion, or modification access to critical data or all Oracle Identity Manager Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data.
Defensive priority
High privileged attackers with network access via HTTP could compromise Oracle Identity Manager Connector, potentially impacting additional products and allowing unauthorized data access or modification.
Recommended defensive actions
- Inventory Oracle Identity Manager Connector instances for versions 12.2.1.4.0 and 14.1.2.1.0
- Apply vendor patches or updates as available
- Monitor for suspicious network activity via HTTP
- Restrict access to critical data and systems
- Implement compensating controls for high privileged attackers
- Review and update asset inventory to ensure accurate tracking of affected systems
- Conduct regular security audits to identify potential vulnerabilities
Evidence notes
The vulnerability is in Oracle Identity Manager Connector, affecting versions 12.2.1.4.0 and 14.1.2.1.0. CVSS 3.1 Base Score is 7.7, indicating high severity. The NVD entry is currently Analyzed. Defenders should verify the presence of these versions in their environments and assess potential impact. Evidence from the CVE record and NVD detail page supports this assessment. Additional information from vendor advisories may be necessary for comprehensive risk evaluation.
Official resources
-
CVE-2026-60534 CVE record
CVE.org
-
CVE-2026-60534 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:53.170Z and has not been modified since then.