>> All posts

CVE-2026-21992: Oracle Identity Manager unauthenticated RCE (out-of-band fix)

The short version: CVE-2026-21992 is an unauthenticated flaw in Oracle Identity Manager and Oracle Web Services Manager that can lead to remote code execution and full takeover. Oracle rarely issues out-of-band Security Alerts — it did for this one, given a 9.8 score on products that guard identity and access. There's no confirmed in-the-wild exploitation or public proof-of-concept as of writing, but the target makes it worth prioritizing. Steady hands — but move.

At a glance

FactDetail
Our severity takeHigh — critical on paper; no confirmed exploitation yet (see below)
CVSS v3.1 (NVD)9.8 — Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS1.0% · 59.1th percentile (2026-07-17)
In CISA KEV?No — not listed as of writing
Known exploited?Not confirmed — no public PoC at time of writing; Oracle has not disclosed in-the-wild activity
Vulnerability typeCWE-306 missing authentication for a critical function → unauthenticated compromise / RCE
Requires authenticated session?No — pre-authentication
AffectedOracle Identity Manager & Oracle Web Services Manager 12.2.1.4.0 and 14.1.2.1.0
Fixed inPer Oracle's out-of-band Security Alert for CVE-2026-21992 — apply the vendor patch

What you need to know

Oracle Identity Manager (OIM) and Oracle Web Services Manager sit in Oracle Fusion Middleware and often live near the network edge, brokering identity and access. CVE-2026-21992 is a missing-authentication flaw: a critical function is reachable without proving who you are. The affected component is REST WebServices in OIM and Web Services Security in OWSM. An unauthenticated attacker with HTTP access can compromise the product, up to full takeover.

Why it deserves priority even without confirmed exploitation:

  • It's unauthenticated and low-complexity. Network access over HTTP is all the attacker needs.
  • Of everything to compromise, this is identity. OIM manages users, credentials, and access; a takeover can expose identity data and provide a beachhead for lateral movement.
  • Oracle broke glass for it. Oracle reserves out-of-band Security Alerts for issues "too critical to wait" for the next quarterly update — it issued one here, revised the next day.
  • There's precedent in the same component. A related OIM REST WebServices flaw (CVE-2025-61757) was exploited in the wild and added to CISA's KEV catalog in late 2025. Oracle hasn't confirmed whether the two are related.

How serious we see it

High — critical on paper, tempered by what we can honestly confirm today.

The base score is a 9.8 and the mechanics justify it: unauthenticated takeover of an identity platform. We hold at High rather than Critical because, at time of writing, there's no confirmed in-the-wild exploitation and no public proof-of-concept, and EPSS is low. That said, the moment a working exploit surfaces for an internet-facing identity server, this jumps — so prioritize it by what it guards, not by the current quiet.

The bounded, reassuring part: it affects specific OIM/OWSM versions, Oracle's fix is published, and exposure is quick to determine.

Recommendations

Straight from Oracle's Security Alert:

  1. Patch now. Apply Oracle's out-of-band fix for CVE-2026-21992 to OIM and OWSM 12.2.1.4.0 / 14.1.2.1.0. Note patches are provided for versions under Premier/Extended Support — older builds may remain exposed.
  2. Harden exposure. Limit who can reach OIM/OWSM interfaces from the internet; identity infrastructure should not be broadly reachable.
  3. Hunt. Review access logs to the REST WebServices endpoints for anomalous unauthenticated requests, especially given prior exploitation of a related flaw.
  4. If you find indicators, respond fully. Rotate credentials and secrets managed by the platform and investigate for lateral movement.
  5. Confirm your exposure first. Verify whether you run an affected OIM/OWSM version and whether it's internet-reachable.

How BreachRisk sees it

BreachRisk works from the outside in. From little more than your domain it discovers internet-facing Oracle Identity Manager interfaces, fingerprints the product and version, and flags exposure tied to this advisory so an exposed, affected instance surfaces near the top of your results. Because there's no reliable, safe public exploit path at time of writing — and because this is sensitive identity infrastructure — BreachRisk detects and flags the exposed, affected server rather than attempting exploitation.

That outside-in view answers the first question fast — do we run an exposed OIM that needs this emergency patch? — so you can act before an exploit becomes commodity.

References

See your cyber risk, proven.