PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73943 Oracle CVE debrief

CVE-2026-73943 is a high-severity vulnerability in the Oracle Identity Manager product, specifically in the OIM Legacy UI component. This vulnerability allows high privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized access to critical data and unauthorized updates to some accessible data. Oracle Identity Manager administrators and security teams should assess exposure, prioritize patch deployment, and monitor for unauthorized access. The CVE record was published on 2026-09-15T20:17:45.310Z and has not been modified since then.

Vendor
Oracle
Product
Identity Manager
CVSS
HIGH 7.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-22
Advisory published
2026-09-15
Advisory updated
2026-09-22

Who should care

Oracle Identity Manager administrators, security teams, and IT personnel responsible for patch management and vulnerability remediation should assess exposure and prioritize patch deployment.

Why it matters

CVE-2026-73943 is a high-severity vulnerability in Oracle Identity Manager that allows high privileged attackers to compromise the system and access critical data. Oracle Identity Manager administrators and security teams should assess exposure, prioritize patch deployment, and monitor for unauthorized access.

  • Potential unauthorized access to critical data.
  • Potential unauthorized updates to some Oracle Identity Manager accessible data.
  • Requires verification of patch deployment for affected versions.
  • Necessitates review of access controls to prevent exploitation.

Technical summary

The vulnerability in Oracle Identity Manager (component: OIM Legacy UI) allows high privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized access to critical data and unauthorized updates to some accessible data. The CVSS 3.1 Base Score is 7.6, indicating a high severity. The vulnerability affects Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0. Oracle Identity Manager administrators and security teams should assess exposure, prioritize patch deployment, and monitor for unauthorized access.

Defensive priority

High priority for Oracle Identity Manager administrators and security teams to assess exposure and verify patch deployment.

Recommended defensive actions

  • Assess exposure of Oracle Identity Manager instances, specifically versions 12.2.1.4.0 and 14.1.2.1.0.
  • Verify patch deployment for affected versions.
  • Monitor for unauthorized access to critical data and unauthorized updates to Oracle Identity Manager accessible data.
  • Review and update access controls to prevent high privileged attackers from exploiting the vulnerability.
  • Perform a thorough review of system logs to detect potential exploitation attempts.
  • Implement compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in Oracle Identity Manager, its impact, and affected versions. The vulnerability affects Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0. The CVSS 3.1 Base Score is 7.6, indicating a high severity. The vulnerability allows high privileged attackers to compromise the system and access critical data. Defenders should verify patch deployment for affected versions and review access controls to prevent exploitation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73943 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73943

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73943 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73943

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.