Oracle Patches Critical Remote Code Execution Flaw in Identity Manager and Web Services Manager
Oracle has released an out-of-band security alert to address a critical vulnerability (CVE-2026-21992) in Oracle Identity Manager and Oracle Web Services Manager. The vulnerability allows for unauthenticated remote code execution, posing a significant risk to organizations using affected versions of the software.
Vulnerability Details
The vulnerability, detailed in Oracle Security Alert Advisory, is remotely exploitable without authentication. Successful exploitation could allow an attacker to execute arbitrary code on a vulnerable system. Tenable reports a CVSSv3 score of 9.8, indicating a critical severity level.
Affected Products and Versions
The following products and versions are affected:
- Oracle Identity Manager, versions 12.2.1.4.0 and 14.1.2.1.0
- Oracle Web Services Manager, versions 12.2.1.4.0 and 14.1.2.1.0
According to CVE Details, the vulnerability impacts the REST WebServices component in Oracle Identity Manager and the Web Services Security component in Oracle Web Services Manager.
Exploitation and Mitigation
Oracle strongly recommends that customers apply the updates or mitigations provided in the security alert as soon as possible. The company emphasizes the importance of remaining on actively supported versions and applying all security patches without delay. BleepingComputer notes that the vulnerability is of low complexity and remotely exploitable over HTTP, without requiring user interaction.
This out-of-band release highlights the severity of the issue, as Oracle typically addresses vulnerabilities during its quarterly Critical Patch Update (CPU) cycle. The next scheduled CPU is in April 2026.
Related Vulnerability
This vulnerability follows the in-the-wild exploitation of a related flaw, CVE-2025-61757, in Oracle Identity Manager’s REST WebServices component in November 2025. CVE-2025-61757 was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.
Support Considerations
Patches are only available for product versions under Premier or Extended Support. Oracle recommends upgrading to supported versions to ensure access to security updates.