Threat reportVulnerabilityTL-2026-0262
Oracle Identity Manager & Web Services Manager Unauthenticated RCE (CVE-2026-21992, CVSS 9.8) — Critical System Takeover via HTTP
Oracle Identity Manager & Web Services Manager (TL-2026-0262), also tracked as Oracle Security Alert CVE-2026-21992, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-03-21. It has no confirmed attribution, affects Oracle Oracle Identity Manager, references 1 CVE (CVE-2026-21992), maps to 15 MITRE ATT&CK techniques (T1059, T1068, T1069), and is covered by 9 detection rules and 15 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-0262
- Threat ID
- TL-2026-0262
- Also known as
- Oracle Security Alert CVE-2026-21992
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- government, financial, healthcare, technology, energy, telecommunications, defense, education, manufacturing
- Target regions
- North America, Europe, Asia Pacific, Middle East, Global
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Oracle Identity Manager & Web Services Manager
Malware and tooling: Groovy, Java
How Oracle Identity Manager & Web Services Manager works
Oracle Identity Manager and Web Services Manager contain a critical unauthenticated remote code execution vulnerability (CVE-2026-21992, CVSS 9.8) in their REST WebServices and Web Services Security components. The flaw allows unauthenticated attackers with network access via HTTP to achieve complete system takeover. Oracle issued an emergency out-of-band patch on March 19, 2026, with public PoC exploits now available on GitHub.
CVE-2026-21992 is a critical remote code execution vulnerability in Oracle Fusion Middleware affecting both Oracle Identity Manager (OIM) and Oracle Web Services Manager (OWSM). The vulnerability resides in the REST WebServices component of OIM and the Web Services Security component of OWSM, affecting versions 12.2.1.4.0 and 14.1.2.1.0 of both products.
The flaw is classified as CWE-306 (Missing Authentication for Critical Function), enabling unauthenticated remote attackers with network access via HTTP to execute arbitrary code on vulnerable systems without any user interaction. The CVSS 3.1 base score of 9.8 reflects the worst-case scenario: network-accessible, low complexity, no privileges required, no user interaction, and complete compromise of confidentiality, integrity, and availability.
Oracle released this patch as an emergency out-of-band security alert on March 19, 2026 — only the ~31st such alert since 2010 (averaging approximately two per year), underscoring the severity. This is notable because the next scheduled Critical Patch Update was not due until April 2026.
The vulnerability follows a troubling pattern in the same product line. CVE-2025-61757, which affected the identical REST WebServices component in the same OIM versions, was added to CISA's Known Exploited Vulnerabilities (KEV) catalog in November 2025 after confirmed active zero-day exploitation dating back to August 2025. That predecessor vulnerability used authentication bypass via metadata suffixes (;.wadl and ?WSDL appended to REST URIs) to reach a Groovy script compilation endpoint, where annotation-processing features allowed arbitrary code execution at compile time. While Oracle has not confirmed whether CVE-2026-21992 is technically related to CVE-2025-61757, the overlap in affected products, components, and versions strongly suggests a similar or adjacent attack surface.
Successful exploitation of CVE-2026-21992 poses severe organizational risk. Attackers compromising Oracle Identity Manager gain the ability to manipulate enterprise identities, roles, and access policies — enabling lateral movement, privilege escalation, and persistent backdoor access across the organization. Compromise of Oracle Web Services Manager allows attackers to modify or disable security policies that protect web service communications, potentially undermining the security posture of all services governed by OWSM.
At the time of Oracle's advisory, no in-the-wild exploitation was confirmed. However, multiple public proof-of-concept exploits have since appeared on GitHub, significantly lowering the barrier to exploitation. Given the precedent set by CVE-2025-61757's rapid weaponization and the availability of PoCs, exploitation in the wild is considered imminent.
MITRE ATT&CK techniques used in TL-2026-0262
execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
privilege-escalation
T1068 Exploitation for Privilege Escalation
discovery
T1069 Permission Groups Discovery; T1087 Account Discovery
command-and-control
T1071 Application Layer Protocol
initial-access
T1190 Exploit Public-Facing Application
collection
T1213 Data from Information Repositories
persistence
T1505 Server Software Component
impact
T1531 Account Access Removal; T1565 Data Manipulation
defense-evasion
T1550 Use Alternate Authentication Material
credential-access
T1552 Unsecured Credentials; T1556 Modify Authentication Process
defense-impairment
Affected products and versions in Oracle Identity Manager & Web Services Manager
- Oracle — Oracle Identity Manager
Vulnerable versions: 12.2.1.4.0; 14.1.2.1.0
Fixed in: Patched via Oracle Security Alert March 2026 - Oracle — Oracle Web Services Manager
Vulnerable versions: 12.2.1.4.0; 14.1.2.1.0
Fixed in: Patched via Oracle Security Alert March 2026 - Oracle — Oracle Fusion Middleware
Vulnerable versions: 12.2.1.4.0; 14.1.2.1.0
Fixed in: Patched via Oracle Security Alert March 2026
Remediation for Oracle Identity Manager & Web Services Manager
Patches
- Apply Oracle Security Alert CVE-2026-21992 patch via Patch Availability Document for Fusion Middleware
- Update Oracle Identity Manager to patched version (consult Oracle's Patch Availability Document)
- Update Oracle Web Services Manager to patched version (consult Oracle's Patch Availability Document)
- Verify CVE-2025-61757 patches are also applied (October 2025 CPU)
Immediate actions
- Apply Oracle's out-of-band security patch for CVE-2026-21992 immediately
- Restrict network access to Oracle Identity Manager and Web Services Manager REST endpoints
- Block external access to OIM REST WebServices and OWSM Web Services Security endpoints at the perimeter firewall
- Monitor HTTP access logs for anomalous POST requests to OIM REST API endpoints, particularly /iam/governance/ paths
- Deploy WAF rules to block unauthenticated access to Oracle Fusion Middleware REST endpoints
- Review and audit all identity management changes made through OIM in the past 30 days for unauthorized modifications
Workarounds
- Restrict HTTP access to Oracle Identity Manager REST WebServices endpoints to trusted internal networks only
- Place Oracle Web Services Manager behind a reverse proxy with authentication enforcement
- Disable or restrict access to REST API endpoints if not operationally required
- Implement IP-based allowlisting for administrative access to Fusion Middleware consoles
Longer-term hardening
- Implement network segmentation to isolate Oracle Fusion Middleware instances from direct internet exposure
- Deploy EDR with behavioral detection for Groovy script execution and Java process anomalies on middleware servers
- Establish continuous vulnerability monitoring for Oracle Fusion Middleware components
- Implement zero-trust architecture for identity management infrastructure access
- Enable comprehensive audit logging for all OIM and OWSM administrative operations
- Conduct regular penetration testing of Oracle Fusion Middleware deployments
CVEs associated with Oracle Identity Manager & Web Services Manager
Weaknesses (CWE) in Oracle Identity Manager & Web Services Manager
Timeline of Oracle Identity Manager & Web Services Manager
- Zero-day exploitation of predecessor CVE-2025-61757 first observed in honeypot environments targeting the same OIM REST WebServices component
- Oracle patches CVE-2025-61757 in October 2025 Critical Patch Update
- Searchlight Cyber publicly discloses CVE-2025-61757 exploitation details and PoC
- CISA adds CVE-2025-61757 to Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation
- Oracle releases security patches for Oracle Identity Manager and Web Services Manager versions 12.2.1.4.0 and 14.1.2.1.0
- Oracle issues emergency out-of-band security alert for CVE-2026-21992 with patches available via Fusion Middleware Patch Availability Document
- Tenable publishes detailed technical analysis and CVE feed confirms 9 public PoC exploits available on GitHub
- Major cybersecurity outlets (The Hacker News, BleepingComputer, Dark Reading, Cybersecurity News) publish advisories urging immediate patching
- As of 2026-05-29, CVE-2026-21992 (Oracle Identity Manager/Web Services Manager unauth RCE, CVSS 9.8) remains PATCHED via Oracle's March 19 out-of-band fix, with no CISA KEV listing and no confirmed in-the-wild exploitation. Public PoCs on GitHub and a for-sale exploit keep risk elevated, so continued monitoring is warranted, but no active campaign is confirmed.
Sources cited for Oracle Identity Manager & Web Services Manager
- Oracle Security Alert Advisory - CVE-2026-21992
- Oracle Critical Patch Updates, Security Alerts and Bulletins
- CVE-2026-21992: Critical Out-of-Band Oracle Identity Manager and Oracle Web Services Manager RCE - Tenable
- Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager - The Hacker News
- Oracle pushes emergency fix for critical Identity Manager RCE flaw - BleepingComputer
- CVE-2026-21992: Critical Out-of-Band Oracle Identity Manager and Oracle Web Services Manager RCE - Security Boulevard
- Patch Now: Oracle Fusion Middleware Has Critical RCE Flaw - Dark Reading
- Oracle Issues Urgent Security Update for Critical RCE Flaw - Cybersecurity News
- CVE-2026-21992 - CVE Feed Detail
- Oracle Fixes High-Severity RCE Vulnerability - GBHackers
- CVE-2025-61757: Oracle Identity Manager Auth Bypass - SOCRadar (predecessor CVE)
- CISA Confirms Exploitation of Oracle Identity Manager Vulnerability (CVE-2025-61757) - SecurityWeek
Detection coverage for TL-2026-0262
As of 2026-03-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0262 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.