#VU126820 Missing Authentication for Critical Function in Identity Manager and Oracle Web Services Manager - CVE-2026-21992
Published: April 22, 2026
Identity Manager
Oracle Web Services Manager
Oracle
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to missing authentication within the REST WebServices component. A remote non-authenticated attacker can send a specially crafted request and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.