logo

Unauthenticated Remote Code Execution in Oracle Identity Manager and Web Services Manager

ID: a5afa6ec-e900-5791-bc27-2a93b7411f6d

STIX ID: report--a5afa6ec-e900-5791-bc27-2a93b7411f6d

Feed Name: Kudelski Security

Threat Score
90/100

Date Published: 2026-03-23

Date Updated: 2026-07-22

...
...

Oracle released patches for CVE-2026-21992 (CVSS 9.8), a critical unauthenticated remote code execution vulnerability affecting Oracle Identity Manager REST WebServices and Oracle Web Services Manager Web Services Security (affected versions 12.2.1.4.0 and 14.1.2.1.0). The flaw enables attackers with network access to execute arbitrary server-side code, potentially allowing lateral movement, persistence, and compromise of identity management; the advisory urges immediate patching, exposure reduction, and enhanced monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.