Oracle Fixes High-Severity RCE Vulnerability Affecting Identity and Web Services Platforms
Oracle has issued a security alert regarding a critical Remote Code Execution (RCE) vulnerability affecting both Oracle Identity Manager and Oracle Web Services Manager.
Oracle has issued a security alert regarding a critical Remote Code Execution (RCE) vulnerability affecting both Oracle Identity Manager and Oracle Web Services Manager.
The vulnerability, identified as CVE-2026-21992, allows remote system compromise without user authentication. Organizations using these Fusion Middleware components should act promptly to prevent potential system takeovers.
The flaw results from a weakness in how network requests are processed, allowing threat actors to send crafted network packets to targeted systems. Successful exploitation can lead to arbitrary code execution on the host server, enabling the deployment of malware, data exfiltration, or further network intrusion.
Oracle assesses the severity of this vulnerability using the Common Vulnerability Scoring System (CVSS) version 3.1. The risk matrix in Oracle's advisory provides context for the potential impact. This vulnerability affects standard network protocols, including secure variants like HTTPS, until updates are applied.
The vulnerability, identified as CVE-2026-21992, allows remote system compromise without user authentication.
The security update addresses vulnerabilities in two Oracle Fusion Middleware products. Administrators should verify deployment versions and apply the necessary patches.
Oracle Identity Manager: Affected versions include 12.2.1.4.0 and 14.1.2.1.0. Refer to Fusion Middleware documentation (KB878741) for mitigation. Oracle Web Services Manager: Affected versions include 12.2.1.4.0 and 14.1.2.1.0. Use the same documentation (KB878741) for mitigation.
Oracle provides patches for versions under Premier Support or Extended Support phases. Unsupported versions were not tested for this vulnerability, but earlier releases may share the defect. Organizations using end-of-life versions must upgrade to supported releases for mitigation.
Administrators should follow Oracle's Software Error Correction Support Policy during updates to ensure stability. Immediate patch deployment is essential to defend against this RCE flaw. Organizations must prioritize these upgrades to maintain security across their identity management infrastructure.
Based on reporting by GBHackers.
