Skip to main content

Oracle Releases Out-of-Band Security Update for Oracle Identity Manager and Oracle Web Services Manager

A critical vulnerability could allow an unauthenticated attacker to takeover Oracle Identity Manager and Oracle Web Services Manager

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

A critical vulnerability could allow an unauthenticated attacker to takeover Oracle Identity Manager and Oracle Web Services Manager


Threat details

Introduction

Oracle has released an out-of-band security update to address a critical vulnerability affecting Oracle Identity Manager (component: REST WebServices) and Oracle Web Services Manager (component: Web Services Security). 

  • CVE-2026-21992 - 'Missing Authentication for Critical Function' vulnerability - CVSSv3 score: 9.8. 

Note: Oracle Web Services Manager is installed with an Oracle Fusion Middleware Infrastructure. 


Remediation advice

Affected organisations are strongly advised to review Oracle Security Alert Advisory - CVE-2026-21992 and apply the relevant updates as soon as possible.



Last edited: 23 March 2026 12:32 pm