{"cve":"CVE-2026-83026","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"12.2.1.4.0"}},{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"14.1.2.1.0"}}],"enrichment":{"confidence":95.0,"confidence_source":"inferred","scores":[{"score":95.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"original":{"product":"Oracle Identity Manager Connector","source":"cna","vendor":"Oracle Corporation"},"product":"identity_manager_connector","vendor":"oracle"}],"created":"2026-09-16T01:30:11.947247+00:00","title":"Physical Access Enables Component Takeover of Oracle Identity Manager Connector","updated":"2026-09-20T12:45:17.432775+00:00","vendors":["oracle","oracle$PRODUCT$identity_manager_connector"]},"epss":{"score":0.00313},"mitre":{"cpes":["cpe:2.3:a:oracle:identity_manager_connector:12.2.1.4.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:identity_manager_connector:14.1.2.1.0:*:*:*:*:*:*:*"],"created":"2026-09-15T20:02:58.706000+00:00","description":"Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector.  While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":8.3,"vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/83xxx/CVE-2026-83026.json","references":["https://www.oracle.com/security-alerts/cspusep2026.html"],"title":null,"updated":"2026-09-16T16:26:04.288000+00:00","vendors":["oracle","oracle$PRODUCT$identity_manager_connector"],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:a:oracle:identity_manager_connector:12.2.1.4.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:identity_manager_connector:14.1.2.1.0:*:*:*:*:*:*:*"],"created":"2026-09-15T20:18:10.600000+00:00","description":"Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector.  While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":8.3,"vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-83026.json","references":["https://www.oracle.com/security-alerts/cspusep2026.html"],"title":null,"updated":"2026-09-22T19:09:31.573000+00:00","vendors":["oracle","oracle$PRODUCT$identity_manager_connector"],"weaknesses":["CWE-284"]},"opencve":{"changes":[{"created":"2026-09-15T20:15:00+00:00","data":[{"details":{"new":"Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector.  While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).","old":null},"type":"description"},{"details":["oracle","oracle$PRODUCT$identity_manager_connector"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:oracle:identity_manager_connector:12.2.1.4.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:identity_manager_connector:14.1.2.1.0:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["oracle","oracle$PRODUCT$identity_manager_connector"],"removed":[]},"type":"vendors"},{"details":{"added":["https://www.oracle.com/security-alerts/cspusep2026.html"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":8.3,"vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"7b464492-daa1-42f2-a375-813ea0e4b2dc"},{"created":"2026-09-16T17:30:00+00:00","data":[{"details":{"added":["CWE-284"],"removed":[]},"type":"weaknesses"},{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"0c94cc34-6347-4f3d-890b-569ffa106d64"},{"created":"2026-09-17T04:45:00+00:00","data":[{"details":{"new":"Unauthenticated Access to Oracle Identity Manager Connector Enables Takeover","old":null},"type":"title"},{"details":{"added":["CWE-287"],"removed":[]},"type":"weaknesses"}],"id":"263603b2-e044-4b64-b063-d94f2c39a959"},{"created":"2026-09-20T11:45:00+00:00","data":[{"details":{"new":null,"old":"Unauthenticated Access to Oracle Identity Manager Connector Enables Takeover"},"type":"title"},{"details":{"added":[],"removed":["CWE-287"]},"type":"weaknesses"}],"id":"77de9d87-a607-4c9d-998d-92e649cb3e9d"},{"created":"2026-09-20T13:00:00+00:00","data":[{"details":{"new":"Physical Access Enables Component Takeover of Oracle Identity Manager Connector","old":null},"type":"title"}],"id":"b98f98c4-e5f6-4fe3-926e-0c3b511eb862"}],"cpes":{"data":["cpe:2.3:a:oracle:identity_manager_connector:12.2.1.4.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:identity_manager_connector:14.1.2.1.0:*:*:*:*:*:*:*"],"providers":["mitre","nvd"]},"created":{"data":"2026-09-15T20:02:58.706000+00:00","provider":"mitre"},"description":{"data":"Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector.  While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":8.3,"vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.00313},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://www.oracle.com/security-alerts/cspusep2026.html"],"providers":["mitre","nvd"]},"title":{"data":"Physical Access Enables Component Takeover of Oracle Identity Manager Connector","provider":"enrichment"},"updated":{"data":"2026-09-20T12:45:17.432775+00:00","provider":"enrichment"},"vendors":{"data":["oracle","oracle$PRODUCT$identity_manager_connector"],"providers":["mitre","nvd","enrichment"]},"weaknesses":{"data":["CWE-284"],"providers":["nvd","vulnrichment"]}},"vulnrichment":{"cpes":[],"created":"2026-09-15T20:02:58.706000+00:00","description":"Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector.  While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":null,"updated":"2026-09-16T15:43:18.213000+00:00","vendors":[],"vulnrichment_repo_path":"2026/83xxx/CVE-2026-83026.json","weaknesses":["CWE-284"]}}