CVE-2026-21992 | Oracle Identity Manager/Web Services Manager 12.2.1.4.0/14.1.2.1.0 Web Service improper authentication (Nessus ID 303226 / WID-SEC-2026-0807)
A vulnerability was found in Oracle Identity Manager and Web Services Manager 12.2.1.4.0/14.1.2.1.0 and classified as critical. Affected is an unknown function of the component Web Service. The manipulation results in improper authentication.
This vulnerability was named CVE-2026-21992. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.