Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992)
Overview
Oracle has issued an emergency patch for a serious vulnerability, identified as CVE-2026-21992, affecting Oracle Identity Manager and Oracle Web Services Manager. This flaw allows attackers to exploit a missing authentication feature, potentially leading to remote code execution without prior authentication. While Oracle hasn't confirmed if this vulnerability has been actively exploited in the wild, they are urging all customers to apply the updates or implement alternative mitigations immediately. The lack of authentication for such a critical function poses significant risks for organizations using these services, emphasizing the need for prompt action to safeguard their systems.
Key Takeaways
- Affected Systems: Oracle Identity Manager, Oracle Web Services Manager
- Action Required: Customers should apply the latest patches provided by Oracle or implement the recommended mitigations as soon as possible.
- Timeline: Newly disclosed
Original Article Summary
Oracle has released an out-of-band patch for a critical and easily exploitable vulnerability (CVE-2026-21992) in Oracle Identity Manager and Oracle Web Services Manager. The company did not say whether the vulnerability has been exploited as a zero-day, but has urged customers to apply the updates or provided mitigations as soon as possible. About CVE-2026-21992 CVE-2026-21992 is caused by missing authentication for a critical function. In Oracle Identity Manager – a solution for provisioning, managing and … More → The post Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992) appeared first on Help Net Security.
Impact
Oracle Identity Manager, Oracle Web Services Manager
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Newly disclosed
Remediation
Customers should apply the latest patches provided by Oracle or implement the recommended mitigations as soon as possible.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Zero-day, Exploit, and 5 more.