CVE-2026-60358
Oracle · Access Manager
A critical vulnerability in the Oracle Access Manager Authentication Engine allows unauthenticated, remote attackers to achieve a full system takeover via HTTP.
Executive summary
A critical, unauthenticated remote code execution vulnerability in Oracle Access Manager allows for total system compromise.
Vulnerability
The vulnerability exists in the Authentication Engine component. It allows an unauthenticated attacker with network access to achieve a complete takeover of the application, representing a total compromise of the authentication infrastructure.
Business impact
With a CVSS score of 10.0, this vulnerability represents the highest level of risk. An attacker gaining control of the Access Manager can compromise the entire identity and access management fabric of an organization, leading to unauthorized access to all protected downstream applications and sensitive corporate data.
Remediation
Immediate Action: Apply the security patches provided in the July 2026 Oracle Critical Patch Update immediately.
Proactive Monitoring: Monitor authentication logs for anomalous activity or unexpected administrative access patterns that may indicate a breach of the authentication engine.
Compensating Controls: Restrict network access to the Oracle Access Manager interface to known, trusted subnets and employ a Web Application Firewall to block suspicious HTTP requests.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability demands immediate attention due to its critical severity and the potential for total system takeover. Security teams should treat this as a top-priority item and ensure that all affected Oracle Access Manager servers are patched immediately to prevent potential exploitation.