Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-35294 -- CVSS 9.9 Vulnerability Briefing

CVE-2026-35294 | CVSS 9.9 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-35294 is a critical-severity vulnerability in Oracle Identity Manager Connector, specifically within the Mainframe Connectors component of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0.

Technical Detail

The flaw resides in the Mainframe Connectors component of Oracle Identity Manager and is described by Oracle as easily exploitable, which typically indicates low attack complexity and no requirement for specialized conditions to trigger. Based on the CVSS score of 9.9 and the product context, successful exploitation likely allows a network-accessible attacker to achieve unauthorized access, privilege escalation, or remote code execution against the affected middleware environment. The near-maximum CVSS score suggests the vulnerability may be exploitable with low or no authentication and carries a high impact across confidentiality, integrity, and availability.

Exploitation Status

No known exploit has been publicly documented or observed as of June 24, 2026. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog, and no proof-of-concept code has been confirmed in public repositories or threat intelligence sources. The absence of known exploitation does not reduce urgency given the critical severity rating and ease of exploitation noted in the vendor advisory.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor associations have been identified in connection with this CVE.

What To Do

Organizations running Oracle Identity Manager Connector versions 12.2.1.4.0 or 14.1.2.1.0 should apply Oracle's patch as a high priority, treating this as an urgent remediation given the critical CVSS score and the vendor's characterization of the flaw as easily exploitable. Administrators should consult Oracle's Critical Patch Update advisory for the specific patch identifier and installation guidance. Until patching is complete, network-level controls should be used to restrict access to the Mainframe Connectors component, limiting exposure to trusted hosts only. Audit logs for the Identity Manager environment should be reviewed for anomalous authentication events or unexpected connector activity. Organizations subject to Oracle support contracts should verify patch availability and confirm version applicability before deployment.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →