CVE-2026-46810
Awaiting Analysis Awaiting Analysis - Queue
Authentication Bypass in Oracle Identity Manager

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Oracle

Description
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: End User Self Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Identity Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Identity Manager accessible data as well as unauthorized read access to a subset of Identity Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
oracle identity_manager 12.2.1.4.0
oracle identity_manager 14.1.2.1.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the Identity Manager product of Oracle Fusion Middleware, specifically in the End User Self Service component. It affects supported versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability is easily exploitable by an unauthenticated attacker who has network access via IIOP (Internet Inter-ORB Protocol).

Successful exploitation allows the attacker to compromise the Identity Manager by gaining unauthorized ability to update, insert, or delete some accessible data, as well as unauthorized read access to a subset of accessible data.

Impact Analysis

The impact of this vulnerability includes unauthorized modification and disclosure of data within the Identity Manager system. An attacker can update, insert, or delete data without authorization, and also read some data they should not have access to.

This can lead to data integrity issues, potential data breaches, and unauthorized changes to identity management information, which could affect system security and trust.

Compliance Impact

This vulnerability allows an unauthenticated attacker with network access to compromise the Oracle Identity Manager, resulting in unauthorized read, update, insert, or delete access to some accessible data. Such unauthorized access to sensitive identity data could potentially lead to non-compliance with data protection regulations like GDPR and HIPAA, which require strict controls over access to personal and sensitive information.

However, the provided information does not explicitly mention the impact on compliance with specific standards or regulations.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-46810. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart