Oracle Fusion Middleware Security Alert Advisory - CVE-2026-21992
Vulnerability ID: CVE-2026-21992
CVSS Score: 9.8
Published: 2026-03-20
CVE-2026-21992 is a critical, unauthenticated remote code execution (RCE) vulnerability affecting the REST WebServices component of Oracle Identity Manager (OIM) and the Web Services Security component of Oracle Web Services Manager (OWSM). Exploitation occurs over standard network protocols without user interaction, enabling a complete compromise of target system infrastructure.
TL;DR
Critical unauthenticated remote code execution vulnerability in Oracle Identity Manager and Oracle Web Services Manager via unsafe Java deserialization, carrying a CVSS score of 9.8.
Technical Details
- CWE ID: CWE-502 (Deserialization of Untrusted Data)
- Attack Vector: Network (AV:N)
- CVSS v3.1 Base Score: 9.8
- EPSS Score: 0.01008 (Percentile: 61.44%)
- Exploit Status: No public exploit available (none)
- CISA KEV Status: Not Listed
- Affected Components: REST WebServices, Web Services Security
Affected Systems
- Oracle Identity Manager REST WebServices
- Oracle Web Services Manager Web Services Security
-
Oracle Identity Manager: 12.2.1.4.0, 14.1.2.1.0 (Fixed in:
Refer to KB878741) -
Oracle Web Services Manager: 12.2.1.4.0, 14.1.2.1.0 (Fixed in:
Refer to KB878741)
Mitigation Strategies
- Apply official Oracle security updates immediately.
- Establish strict global JEP 290 filters using the recommended Oracle blocklist configurations.
- Implement network segmentation to restrict HTTP access to Oracle Identity Manager and Web Services Manager interfaces.
Remediation Steps:
- Identify vulnerable systems running OIM and OWSM versions 12.2.1.4.0 or 14.1.2.1.0.
- Download the official patches corresponding to Oracle Bug ID 38965612 and 39023318 via Support Note KB878741.
- Deploy the updates to the WebLogic/Fusion Middleware infrastructure following standard OPatch procedures.
- Configure Java system properties to enforce the JEP 290 reference filter rules as outlined in Support Note 2591118.
- Validate the exclusion of Java serialization sequences from perimeter HTTP requests using firewall and WAF enforcement.
References
- Official Oracle HTML Advisory
- Official Verbose Advisory Risk Matrices
- Official Oracle CSAF JSON
- CVE Record Database
Read the full report for CVE-2026-21992 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)