Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
A serious security vulnerability affecting Identity Manager and Web Services Manager that could be used to accomplish remote code execution has been fixed by Oracle through security patches.
The vulnerability has a CVSS score of 9.8 out of a possible 10.0, and it is tagged as CVE-2026-21992.
According to an Oracle alert, this vulnerability can be remotely exploited without authentication. This vulnerability could lead to remote code execution if it is successfully exploited.
CVE-2026-21992 affects the following versions -
Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0
Oracle Web Services Manager versions 12.2.1.4.0 and 14.1.2.1.0
A description of the vulnerability in the NIST National Vulnerability Database (NVD) states that it is "easily exploitable" and m...





