PatchSiren cyber security CVE debrief
CVE-2026-73943 Oracle CVE debrief
CVE-2026-73943 is a high-severity vulnerability in the Oracle Identity Manager product, specifically in the OIM Legacy UI component. This vulnerability allows high privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized access to critical data and unauthorized updates to some accessible data. Oracle Identity Manager administrators and security teams should assess exposure, prioritize patch deployment, and monitor for unauthorized access. The CVE record was published on 2026-09-15T20:17:45.310Z and has not been modified since then.
- Vendor
- Oracle
- Product
- Identity Manager
- CVSS
- HIGH 7.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-22
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-22
Who should care
Oracle Identity Manager administrators, security teams, and IT personnel responsible for patch management and vulnerability remediation should assess exposure and prioritize patch deployment.
Why it matters
CVE-2026-73943 is a high-severity vulnerability in Oracle Identity Manager that allows high privileged attackers to compromise the system and access critical data. Oracle Identity Manager administrators and security teams should assess exposure, prioritize patch deployment, and monitor for unauthorized access.
- Potential unauthorized access to critical data.
- Potential unauthorized updates to some Oracle Identity Manager accessible data.
- Requires verification of patch deployment for affected versions.
- Necessitates review of access controls to prevent exploitation.
Technical summary
The vulnerability in Oracle Identity Manager (component: OIM Legacy UI) allows high privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized access to critical data and unauthorized updates to some accessible data. The CVSS 3.1 Base Score is 7.6, indicating a high severity. The vulnerability affects Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0. Oracle Identity Manager administrators and security teams should assess exposure, prioritize patch deployment, and monitor for unauthorized access.
Defensive priority
High priority for Oracle Identity Manager administrators and security teams to assess exposure and verify patch deployment.
Recommended defensive actions
- Assess exposure of Oracle Identity Manager instances, specifically versions 12.2.1.4.0 and 14.1.2.1.0.
- Verify patch deployment for affected versions.
- Monitor for unauthorized access to critical data and unauthorized updates to Oracle Identity Manager accessible data.
- Review and update access controls to prevent high privileged attackers from exploiting the vulnerability.
- Perform a thorough review of system logs to detect potential exploitation attempts.
- Implement compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in Oracle Identity Manager, its impact, and affected versions. The vulnerability affects Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0. The CVSS 3.1 Base Score is 7.6, indicating a high severity. The vulnerability allows high privileged attackers to compromise the system and access critical data. Defenders should verify patch deployment for affected versions and review access controls to prevent exploitation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73943 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73943
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73943 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73943
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspusep2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.