Signal is active with 1 mentions in latest observed window
Immediate actions
Track advisory updates for patch or workaround availability
Recommended action window: Monitor and triage in normal cycle
NVD description
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
CVE-2026-34285 Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. … https://www.cve.org/CVERecord?id=CVE-2026-34285
Post summary
The text is a concise CVE record reference that lists the affected product and version but provides no actionable or technical details beyond that.
CVE-2026-34285 | Oracle Identity Manager Connector | Unauthenticated Data Access
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager Connector 12.2.1.4.0. Successful attacks result in unauthorized creation, deletion, modification, or access to critical data. No privileges or user interaction required.
Severity: Critical
Exploitation: Unknown
Public PoC: Unknown
Affected Product: Oracle Identity Manager Connector
Affected Version: 12.2.1.4.0
Sources
Vendor: https://www.oracle.com/security-alerts/cpuapr2026.html
Post summary
An advisory discloses a critical unauthenticated data‑access vulnerability in Oracle Identity Manager Connector 12.2.1.4.0, with no public PoC, exploit code, or evidence of active exploitation, and no patch details provided.