CVE-2026-34286Disclosure(oracle / identity_manager_connector)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • identity_manager_connector

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-22); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
identity_manager_connector

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-22: 1Mentions · 2026-04-26: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-26: 104-2204-26
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-34286 Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. … https://www.cve.org/CVERecord?id=CVE-2026-34286

    Post summary

    The text announces CVE‑2026‑34286 as a vulnerability in Oracle Identity Manager Connector 12.2.1.4.0, without additional details on exploitation, PoC, patch, or false‑positive status.

    00000151
    57.3K followersView on X
  • Red Hornet Intel@RedHornet_Intel
    Disclosure

    CVE-2026-34286 | Oracle Identity Manager Connector | Unauthenticated Data Access Easily exploitable vulnerability in Oracle Fusion Middleware (Core) allows unauthenticated attacker with network access via HTTPS to compromise the product. Successful attacks enable unauthorized creation, deletion, modification, or read access to all critical data. CVSS 3.1 Base Score 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). Severity: Critical Exploitation: Unknown Public PoC: Unknown Affected Product: Oracle Identity Manager Connector Affected Version: 12.2.1.4.0 Sources Vendor: https://www.oracle.com/security-alerts/cpuapr2026.html

    Post summary

    The text announces a critical unauthenticated data‑access flaw in Oracle Identity Manager Connector, detailing its impact and CVSS score but providing no PoC, exploit code, or patch information.

    0000056
    8 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporacleidentity_manager_connector12.2.1.4.0--

Explore more