# Oracle Identity Manager & Web Services Manager Unauthenticated RCE (CVE-2026-21992, CVSS 9.8) — Critical System Takeover via HTTP

> Oracle Identity Manager and Web Services Manager contain a critical unauthenticated remote code execution vulnerability (CVE-2026-21992, CVSS 9.8) in their REST WebServices and Web Services Security components. The flaw allows unauthenticated attackers with network access via HTTP to achieve complete system takeover. Oracle issued an emergency out-of-band patch on March 19, 2026, with public PoC exploits now available on GitHub.

- **Published:** 2026-03-21T12:00:00Z
- **Last reviewed:** 2026-03-21T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0262
- **ID:** TL-2026-0262
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-21992

## Description

CVE-2026-21992 is a critical remote code execution vulnerability in Oracle Fusion Middleware affecting both Oracle Identity Manager (OIM) and Oracle Web Services Manager (OWSM). The vulnerability resides in the REST WebServices component of OIM and the Web Services Security component of OWSM, affecting versions 12.2.1.4.0 and 14.1.2.1.0 of both products.

The flaw is classified as CWE-306 (Missing Authentication for Critical Function), enabling unauthenticated remote attackers with network access via HTTP to execute arbitrary code on vulnerable systems without any user interaction. The CVSS 3.1 base score of 9.8 reflects the worst-case scenario: network-accessible, low complexity, no privileges required, no user interaction, and complete compromise of confidentiality, integrity, and availability.

Oracle released this patch as an emergency out-of-band security alert on March 19, 2026 — only the ~31st such alert since 2010 (averaging approximately two per year), underscoring the severity. This is notable because the next scheduled Critical Patch Update was not due until April 2026.

The vulnerability follows a troubling pattern in the same product line. CVE-2025-61757, which affected the identical REST WebServices component in the same OIM versions, was added to CISA's Known Exploited Vulnerabilities (KEV) catalog in November 2025 after confirmed active zero-day exploitation dating back to August 2025. That predecessor vulnerability used authentication bypass via metadata suffixes (;.wadl and ?WSDL appended to REST URIs) to reach a Groovy script compilation endpoint, where annotation-processing features allowed arbitrary code execution at compile time. While Oracle has not confirmed whether CVE-2026-21992 is technically related to CVE-2025-61757, the overlap in affected products, components, and versions strongly suggests a similar or adjacent attack surface.

Successful exploitation of CVE-2026-21992 poses severe organizational risk. Attackers compromising Oracle Identity Manager gain the ability to manipulate enterprise identities, roles, and access policies — enabling lateral movement, privilege escalation, and persistent backdoor access across the organization. Compromise of Oracle Web Services Manager allows attackers to modify or disable security policies that protect web service communications, potentially undermining the security posture of all services governed by OWSM.

At the time of Oracle's advisory, no in-the-wild exploitation was confirmed. However, multiple public proof-of-concept exploits have since appeared on GitHub, significantly lowering the barrier to exploitation. Given the precedent set by CVE-2025-61757's rapid weaponization and the availability of PoCs, exploitation in the wild is considered imminent.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1203 Exploitation for Client Execution
- T1505 Server Software Component
- T1068 Exploitation for Privilege Escalation
- T1685 Disable or Modify Tools
- T1556 Modify Authentication Process
- T1552 Unsecured Credentials
- T1087 Account Discovery
- T1069 Permission Groups Discovery
- T1550 Use Alternate Authentication Material
- T1213 Data from Information Repositories
- T1071 Application Layer Protocol
- T1531 Account Access Removal
- T1565 Data Manipulation

## Sources

- [Oracle Security Alert Advisory - CVE-2026-21992](https://www.oracle.com/security-alerts/alert-cve-2026-21992.html)
- [Oracle Critical Patch Updates, Security Alerts and Bulletins](https://www.oracle.com/security-alerts/)
- [CVE-2026-21992: Critical Out-of-Band Oracle Identity Manager and Oracle Web Services Manager RCE - Tenable](https://www.tenable.com/blog/cve-2026-21992-critical-out-of-band-oracle-identity-manager-and-oracle-web-services-manager)
- [Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager - The Hacker News](https://thehackernews.com/2026/03/oracle-patches-critical-cve-2026-21992.html)
- [Oracle pushes emergency fix for critical Identity Manager RCE flaw - BleepingComputer](https://www.bleepingcomputer.com/news/security/oracle-pushes-emergency-fix-for-critical-identity-manager-rce-flaw/)
- [CVE-2026-21992: Critical Out-of-Band Oracle Identity Manager and Oracle Web Services Manager RCE - Security Boulevard](https://securityboulevard.com/2026/03/cve-2026-21992-critical-out-of-band-oracle-identity-manager-and-oracle-web-services-manager-remote-code-execution-vulnerability/)
- [Patch Now: Oracle Fusion Middleware Has Critical RCE Flaw - Dark Reading](https://www.darkreading.com/vulnerabilities-threats/patch-oracle-fusion-middleware-rce-flaw)
- [Oracle Issues Urgent Security Update for Critical RCE Flaw - Cybersecurity News](https://cybersecuritynews.com/oracle-urgent-security-update/)
- [CVE-2026-21992 - CVE Feed Detail](https://cvefeed.io/vuln/detail/CVE-2026-21992)
- [Oracle Fixes High-Severity RCE Vulnerability - GBHackers](https://gbhackers.com/oracle-fixes-high-severity-rce-vulnerability/)
- [CVE-2025-61757: Oracle Identity Manager Auth Bypass - SOCRadar (predecessor CVE)](https://socradar.io/blog/cve-2025-61757-oracle-identity-manager/)
- [CISA Confirms Exploitation of Oracle Identity Manager Vulnerability (CVE-2025-61757) - SecurityWeek](https://www.securityweek.com/cisa-confirms-exploitation-of-recent-oracle-identity-manager-vulnerability/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0262
