CVE-2026-35269: High severity Oracle Oracle Identity Manager vulnerability
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Identity Manager accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to the Identity Manager REST WebServices HTTP endpoints to trusted IPs only (apply firewall/ACL rules at the perimeter and internal network segments to block HTTP access from untrusted networks).
- Compensating control
Deploy a Web Application Firewall (WAF) or intrusion prevention controls in front of Identity Manager REST WebServices to detect and block malicious HTTP requests, or otherwise block/inspect HTTP traffic to the component if the service is not required externally.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35269?
The severity of CVE-2026-35269 is classified as high with a score of 7.5.
How do I fix CVE-2026-35269?
To remediate CVE-2026-35269, update to the latest patched version of Oracle Identity Manager that is not affected by the vulnerability.
What component is affected by CVE-2026-35269?
CVE-2026-35269 affects the REST WebServices component of the Oracle Identity Manager product.
Who is at risk from CVE-2026-35269?
Unauthenticated attackers with network access via HTTP can exploit CVE-2026-35269 to compromise the Identity Manager.
What versions are impacted by CVE-2026-35269?
The affected versions of Oracle Identity Manager are 12.2.1.4.0 and 14.1.2.1.0.