Missing Authentication for Critical Function in Identity Manager and Oracle Web Services Manager - CVE-2026-21992

 

Missing Authentication for Critical Function in Identity Manager and Oracle Web Services Manager - CVE-2026-21992

Published: April 22, 2026


Vulnerability identifier: #VU126820
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-21992
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to missing authentication within the REST WebServices component. A remote non-authenticated attacker can send a specially crafted request and execute arbitrary code on the system.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Identity Manager
Oracle Web Services Manager

How to mitigate CVE-2026-21992

Install updates from vendor's website.


External References

Related Security Bulletins