CVE-2026-21992 is a critical unauthenticated remote code execution vulnerability impacting Oracle Identity Manager and Oracle Web Services Manager, specifically versions 12.2.1.4.0 and 14.1.2.1.0. This easily exploitable flaw allows an unauthenticated attacker with network access via HTTP to fully compromise affected systems. Successful attacks can result in a complete takeover, leading to a total loss of confidentiality, integrity, and availability, as reflected by its CVSS 3.1 score of 9.8. Although not yet listed on the CISA KEV catalog and lacking public exploit code, this vulnerability is on the Hot List and has generated significant community discussion and media coverage, indicating a high potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2.1.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:* | ||
14.1.2.1.0CPE matchmatch criteria | cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:* | ||
12.2.1.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:web_services_manager:12.2.1.4.0:*:*:*:*:*:*:* | ||
14.1.2.1.0CPE matchmatch criteria | cpe:2.3:a:oracle:web_services_manager:14.1.2.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.