CVE-2026-46792: Critical severity Oracle Identity Manager Connector (Generic Unix Connector) vulnerability
Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager Connector. While the vulnerability is in Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Identity Manager Connector. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the HTTP interface for Identity Manager Connector if possible. If disabling is not feasible, configure the connector to only accept HTTP connections from trusted management networks or localhost, or require access via a secure VPN.
Identity Manager Connector (Generic Unix Connector) HTTP access = disabled or restricted - Compensating control
Restrict network access to the Identity Manager Connector HTTP port at the network perimeter (firewall, ACLs or WAF) to trusted management IPs and networks only.
- Compensating control
Isolate systems running Identity Manager Connector from other production systems and sensitive resources to prevent lateral movement; implement network segmentation and strict access controls between segments.
- Operational
Monitor logs and network traffic for signs of exploitation and prepare incident response procedures. Apply vendor-supplied updates or patches for Identity Manager Connector as soon as they are released and follow Oracle guidance.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46792?
CVE-2026-46792 has a critical severity rating of 9.9.
How do I fix CVE-2026-46792?
To fix CVE-2026-46792, update the Oracle Identity Manager Connector to a patched version not vulnerable to this issue.
What systems are impacted by CVE-2026-46792?
CVE-2026-46792 affects Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0.
What are the potential impacts of CVE-2026-46792?
Exploitation of CVE-2026-46792 could allow a low privileged attacker to compromise Identity Manager with high confidentiality, integrity, and availability impacts.
Is there a known exploit for CVE-2026-46792?
Yes, CVE-2026-46792 is considered easily exploitable by attackers with low privileges and network access.