
Update: It was added that Oracle wouldn’t say if the security flaw was actively being used.
Oracle has issued an emergency security patch for a serious remote code execution vulnerability, identified as CVE-2026-21992, that doesn’t require authentication in Identity Manager and Web Services Manager.
Oracle Identity Manager is a tool for managing user accounts and access rights within an organization, while Oracle Web Services Manager offers security and management capabilities for web services.
In a warning issued yesterday, Oracle is “strongly” urging clients to install the fixes immediately.
“This Security Alert is about CVE-2026-21992 in Oracle Identity Manager and Oracle Web Services Manager. This vulnerability can be exploited remotely without any login required. Successful exploitation could lead to remote code execution,” according to the security advisory.
“Oracle highly advises users to apply the provided updates or workarounds in this Security Alert as fast as possible. Oracle always suggests that users stay on versions that are supported and promptly install all Security Alerts and Critical Patch Update security fixes.”
The CVE-2026-21992 vulnerability has a CVSS v3.1 score of 9.8, indicating critical severity, and affects Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0, and Oracle Web Services Manager versions 12.2.1.4.0 and 14.1.2.1.0.
Oracle explains that the vulnerability is easy to exploit, can be triggered remotely via HTTP, and doesn’t need authentication or any interaction from users, making exploitation more likely on publicly accessible servers.
The solution was released through its Security Alert program, which provides unscheduled fixes or ways to reduce the impact of serious vulnerabilities or those being exploited. Oracle also notes that these patches are only available for versions that are still under Premier or Extended Support, leaving older, unsupported versions potentially vulnerable.
Oracle has not revealed whether this vulnerability has been exploited and declined to comment when BleepingComputer inquired.
In a separate blog post published today, Oracle reiterated the seriousness of CVE-2026-21992 and advised customers to consult the security alert for comprehensive details and patching information.
#addresses #code #execution #identity #manager. #news #oracle #patch #remote #severe #urgent #vulnerability — News
© Bulletproof Servers. All rights reserved.