Cyber Posture

CVE-2026-34290

High

Published: 21 April 2026

Published
21 April 2026
Modified
23 April 2026
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0005 14.4th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-34290 is a high-severity Uncontrolled Resource Consumption (CWE-400) vulnerability in Oracle Identity Manager Connector. Its CVSS base score is 7.5 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Application or System Exploitation (T1499.004); ranked at the 14.4th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 SC-5 (Denial-of-service Protection) and SC-6 (Resource Availability).

Threat & Defense at a Glance

What attackers do: exploitation maps to Application or System Exploitation (T1499.004). What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Flaw remediation requires applying the Oracle Critical Patch Update to directly fix the uncontrolled resource consumption vulnerability in the Identity Manager Connector.

preventdetect

Denial-of-service protection implements techniques to prevent and detect resource exhaustion attacks like the unauthenticated TCP-based DoS in this CVE.

prevent

Resource availability enforces limits on resource allocation to mitigate unauthorized consumption leading to hangs or crashes as exploited in this vulnerability.

MITRE ATT&CK Enterprise TechniquesAI

T1499.004 Application or System Exploitation Impact
Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users.
Why these techniques?

Vulnerability enables remote unauthenticated exploitation causing resource consumption leading to crash/hang and DoS, directly mapping to Application or System Exploitation under Endpoint Denial of Service.

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Identity Manager Connector. Successful…

more

attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Identity Manager Connector. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Deeper analysisAI

CVE-2026-34290 is a vulnerability in the Core component of the Oracle Identity Manager Connector product within Oracle Fusion Middleware. The supported version affected is 12.2.1.4.0. This issue, linked to CWE-400 (Uncontrolled Resource Consumption), carries a CVSS 3.1 base score of 7.5 (vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), with high availability impact but no confidentiality or integrity effects.

An unauthenticated attacker with network access via TCP can easily exploit this vulnerability to compromise the Oracle Identity Manager Connector. Successful exploitation enables the attacker to cause a hang or frequently repeatable crash, resulting in a complete denial of service (DoS) against the affected component.

The Oracle Critical Patch Update advisory provides details on mitigation and patches: https://www.oracle.com/security-alerts/cpuapr2026.html.

Details

CWE(s)

Affected Products

oracle
identity manager connector
12.2.1.4.0

CVEs Like This One

CVE-2026-34282Same vendor: Oracle
CVE-2026-21945Same vendor: Oracle
CVE-2025-21549Same vendor: Oracle
CVE-2026-34285Same product: Oracle Identity Manager Connector
CVE-2026-34286Same product: Oracle Identity Manager Connector
CVE-2026-34287Same product: Oracle Identity Manager Connector
CVE-2025-21547Same vendor: Oracle
CVE-2025-21521Same vendor: Oracle
CVE-2025-21545Same vendor: Oracle
CVE-2026-35245Same vendor: Oracle

References