# Oracle Identity Manager RCE Flaw Disclosed

Published: 2026-03-23 · Severity: medium · Sectors: government-national
Canonical: https://vorant.io/reports/da19494e-a7e0-571c-8418-f482347001cc/oracle-identity-manager-rce-flaw-disclosed

> An unauthenticated remote code execution vulnerability affects Oracle Identity Manager and Oracle Web Services Manager, with no known active exploitation yet.

CIS/MS-ISAC issued an advisory for CVE-2026-21992, a remotely exploitable vulnerability without authentication affecting Oracle Identity Manager and Oracle Web Services Manager (versions 12.2.1.4.0 and 14.1.2.1.0). Successful exploitation could allow an attacker to execute arbitrary code, install programs, manipulate or delete data, or create new accounts with full privileges, with impact scaling based on the privilege level of the compromised account.

There are currently no reports of in-the-wild exploitation. The advisory maps the flaw to MITRE ATT&CK's Exploit Public-Facing Application technique under the Initial Access tactic, and recommends prompt patching, least-privilege configurations, network segmentation, vulnerability scanning, and exploit protection measures to mitigate risk for government, business, and home user environments.

## Mentioned in this report

- Vulnerabilities: CVE-2026-21992

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-oracle-products-could-allow-for-remote-code-execution_2026-024

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/da19494e-a7e0-571c-8418-f482347001cc/oracle-identity-manager-rce-flaw-disclosed.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
