Oracle Identity Manager RCE Flaw Disclosed
An unauthenticated remote code execution vulnerability affects Oracle Identity Manager and Oracle Web Services Manager, with no known active exploitation yet.
CIS/MS-ISAC issued an advisory for CVE-2026-21992, a remotely exploitable vulnerability without authentication affecting Oracle Identity Manager and Oracle Web Services Manager (versions 12.2.1.4.0 and 14.1.2.1.0). Successful exploitation could allow an attacker to execute arbitrary code, install programs, manipulate or delete data, or create new accounts with full privileges, with impact scaling based on the privilege level of the compromised account.
There are currently no reports of in-the-wild exploitation. The advisory maps the flaw to MITRE ATT&CK's Exploit Public-Facing Application technique under the Initial Access tactic, and recommends prompt patching, least-privilege configurations, network segmentation, vulnerability scanning, and exploit protection measures to mitigate risk for government, business, and home user environments.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-oracle-products-could-allow-for-remote-code-execution_2026-024
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free