Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager
Oracle has released a Security Alert to address a critical remote code execution (RCE) vulnerability, designated as CVE-2026-21992. This vulnerability affects Oracle Identity Manager and Oracle Web Services Manager within the Fusion Middleware suite.
Oracle has released a Security Alert to address a critical remote code execution (RCE) vulnerability, designated as CVE-2026-21992. This vulnerability affects Oracle Identity Manager and Oracle Web Services Manager within the Fusion Middleware suite.
The vulnerability has been assigned a CVSS 3.1 base score of 9.8, indicating a high severity level. It is an unauthenticated, remotely exploitable flaw that does not require user interaction or special privileges. The attack vector is network-based and exhibits low complexity, requiring only HTTP access to an exposed endpoint to potentially trigger remote code execution.
The impact on Confidentiality, Integrity, and Availability is rated as High, suggesting that successful exploitation could result in full system control by an attacker.
In Oracle Identity Manager, the vulnerability is located in the REST Web Services component, while in Oracle Web Services Manager, it resides within the Web Services Security module. The presence of Web Services Manager in conjunction with Oracle Fusion Middleware Infrastructure increases the potential attack surface across enterprise deployments.
The following product versions are impacted:
Oracle has released a Security Alert to address a critical remote code execution (RCE) vulnerability, designated as CVE-2026-21992.
Oracle Identity Manager: 12.2.1.4.0, 14.1.2.1.0 Oracle Web Services Manager: 12.2.1.4.0, 14.1.2.1.0
These versions are part of the Fusion Middleware patch track, with patch information available on Oracle's Security Alert advisory page and My Oracle Support (Document ID KB878741).
Given the CVSS score of 9.8 and the absence of an authentication requirement, this vulnerability is particularly critical for organizations with internet-facing Oracle Fusion Middleware deployments. Oracle Identity Manager and Oracle Web Services Manager are integral components within large enterprise and government environments. Exploitation could lead to full system compromise, credential theft, or lateral movement across connected systems.
Oracle recommends immediate application of available patches. The alert was initially released on Thu, Mar 19, 2026, and updated on Fri, Mar 20, 2026. Organizations using unsupported versions should upgrade to a supported release, as patches are provided only for versions under Premier Support or Extended Support as per Oracle’s Lifetime Support Policy.
Security teams should prioritize patching externally accessible instances and review HTTP/HTTPS exposure of REST Web Services and Web Services Security endpoints until remediation is complete. Further details can be found on Oracle’s official Security Alerts portal.
Based on reporting by Cyber Security News.
