CVE-2026-35268 -- CVSS 9.9 Vulnerability Briefing
CVE-2026-35268 | CVSS 9.9 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-35268 is a critical vulnerability in the Core component of Oracle Identity Manager, part of the Oracle Fusion Middleware product family, affecting versions 12.2.1.4.0 and 14.1.2.1.0.
Technical Detail
The flaw is described as easily exploitable and carries a CVSS score of 9.9, indicating near-maximum severity with a broad attack surface and high impact across confidentiality, integrity, and availability. Based on the scoring profile and the Identity Manager attack surface, the vulnerability likely permits a low-privileged or unauthenticated network-accessible attacker to achieve unauthorized access or control over the identity management system, potentially enabling privilege escalation or full compromise of managed identities and connected resources. The truncated description prevents full technical characterization, but the CVSS score and "easily exploitable" language indicate minimal attack complexity and no required user interaction.
Exploitation Status
No known exploit exists at this time. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog as of June 24, 2026, and exploit maturity is currently assessed as none. This does not reduce the urgency of patching given the critical CVSS score and the high-value nature of identity management infrastructure as a target.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor associations have been identified for this CVE. Organizations should treat identity management systems as high-priority targets regardless, as they are routinely sought by both nation-state actors and financially motivated groups for credential harvesting and lateral movement.
What To Do
Apply Oracle's patch for Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 as part of Oracle's standard Critical Patch Update cycle. Given the 9.9 CVSS score and the ease of exploitation, patching should be treated as urgent and prioritized ahead of routine maintenance windows. If immediate patching is not feasible, restrict network access to the Identity Manager Core component to trusted administrative networks only, and audit current access controls and authentication configurations. Monitor Identity Manager logs for anomalous authentication events, unexpected privilege changes, or unusual API activity. Verify that no unauthorized accounts or role assignments have been introduced in the interim period before patching is complete.