Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1047 articles · 105207 vulns · 38/41 feeds (7d)
← Back to list
9.8
CVE-2026-21992EXPLOITED
oracle · identity_manager

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Servi

Description

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager and Oracle Web Services Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager and Oracle Web Services Manager. Note: Oracle Web Services Manager is installed with an Oracle Fusion Middleware Infrastructure. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected Products

VendorProductVersions
oracleidentity_manager12.2.1.4.0 without the latest security patch, 14.1.2.1.0 without the latest security patch

References

  • https://www.oracle.com/security-alerts/alert-cve-2026-21992.html(Vendor Advisory)

Related News (4 articles)

Tier C
Cisco Talos14h ago
A puppet made me cry and all I got was this t-shirt
→ No new info (linked only)
Tier D
The Hacker News5d ago
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
→ No new info (linked only)
Tier B
CCCS Canada6d ago
Oracle security advisory (AV26-261)
→ No new info (linked only)
Tier D
Heise Security7d ago
Oracle Identity Manager: Update außer der Reihe gegen Codeschmuggel-Lücke
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-306, CVE-2026-21992
Published3/20/2026
Last enriched9h agov3
Trending Score64
Source articles4
Independent4
Info Completeness9/14
Missing: epss, kev, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Version History

v3
Last enriched 9h ago
v3Tier B9h ago

Updated exploit availability to true, marked as actively exploited, and added new CVE-2026-21992.

exploitAvailableactivelyExploitedcweIds
via CCCS Canada
v2Tier B9h ago

Updated affected versions to include specific versions without the latest security patch and marked the vulnerability as actively exploited.

affectedVersions
via CERT-FR
v110h ago

Initial creation