Oracle Identity Manager & Web Services Manager Unauthenticated RCE (CVE-2026-21992, CVSS 9.8) — Critical System Takeover via HTTP — Threadlinqs Intelligence
As of 2026-05-30, Oracle Identity Manager & Web Services Manager Unauthenticated RCE (CVE-2026-21992, CVSS 9.8) — Critical System Takeover via HTTP is a critical-severity vulnerability threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-0262 · Severity: CRITICAL · CVSS: 9.8 · Status: PATCHED · Category: VULNERABILITY
Attribution: N/A · UNKNOWN
Oracle Identity Manager and Web Services Manager contain a critical unauthenticated remote code execution vulnerability (CVE-2026-21992, CVSS 9.8) in their REST WebServices and Web Services Security
CVE-2026-21992 is a critical remote code execution vulnerability in Oracle Fusion Middleware affecting both Oracle Identity Manager (OIM) and Oracle Web Services Manager (OWSM). The vulnerability resides in the REST WebServices component of OIM and the Web Services Security component of OWSM, affecting versions 12.2.1.4.0 and 14.1.2.1.0 of both products.
The flaw is classified as CWE-306 (Missing Authentication for Critical Function), enabling unauthenticated remote attackers with network access via HTTP to execute arbitrary code on vulnerable systems without any user interaction. The CVSS 3.1 base score of 9.8 reflects the worst-case scenario: network-accessible, low complexity, no privileges required, no user interaction, and complete compromise of confidentiality, integrity, and availability.
Oracle released this patch as an emergency out-of-band security alert on March 19, 2026 — only the ~31st such alert since 2010 (averaging approximately two per year), underscoring the severity. This is notable because the next scheduled Critical Patch Update was not due until April 2026.
The vulnerability follows a troubling pattern in the same product line. CVE-2025-61757, which affected the identical REST WebServices component in the same OIM versions, was added to CISA's Known Exploited Vulnerabilities (KEV) catalog in November 2025 after confirmed active zero-day exploitation dating back to August 2025. That predecessor vulnerability used authentication bypass via metadata suffixes (;.wadl and ?WSDL appended to REST URIs) to reach a Groovy script compilation endpoint, where annotation-processing features allowed arbitrary code execution at compile time. While Oracle has not confirmed whether CVE-2026-21992 is technically related to CVE-2025-61757, the overlap in affected products, components, and versions strongly suggests a similar or adjacent attack surface.
Successful exploitation of CVE-2026-21992 poses severe organizational risk. Attackers compromising Oracle Identity Manager gain the ability to manipulate enterprise identities, roles, and access policies — enabling lateral movement, privilege escalation, and persistent backdoor access across the organization. Compromise of Oracle Web Services Manager allows attackers to modify or disable security policies that protect web service communications, potentially undermining the security posture of all services governed by OWSM.
At the time of Oracle's advisory, no in-the-wild exploitation was confirmed. However, multiple public proof-of-concept exploits have since appeared on GitHub, significantly lowering the barrier to exploitation. Given the precedent set by CVE-2025-61757's rapid weaponization and the availability of PoCs, exploitation in the wild is considered imminent.
Target sectors: government, financial, healthcare, technology, energy, telecommunications, defense, education, manufacturing
Target regions: North America, Europe, Asia Pacific, Middle East, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-21992, T1190, T1059, T1203, T1505, T1068, T1562, T1556, T1552, T1087, T1069