Oracle Releases Out-of-Band Security Update for Oracle Identity Manager and Oracle Web Services Manager
A critical vulnerability could allow an unauthenticated attacker to takeover Oracle Identity Manager and Oracle Web Services Manager
Summary
A critical vulnerability could allow an unauthenticated attacker to takeover Oracle Identity Manager and Oracle Web Services Manager
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Oracle has released an out-of-band security update to address a critical vulnerability affecting Oracle Identity Manager (component: REST WebServices) and Oracle Web Services Manager (component: Web Services Security).
- CVE-2026-21992 - 'Missing Authentication for Critical Function' vulnerability - CVSSv3 score: 9.8.
Note: Oracle Web Services Manager is installed with an Oracle Fusion Middleware Infrastructure.
Remediation advice
Affected organisations are strongly advised to review Oracle Security Alert Advisory - CVE-2026-21992 and apply the relevant updates as soon as possible.
Definitive source of threat updates
Last edited: 23 March 2026 12:32 pm