CVE-2026-60726

8.8

Oracle · Oracle Access Manager

A vulnerability in the Authentication Engine of Oracle Access Manager allows a low privileged attacker with network access via HTTP to compromise the system.

Executive summary

A critical vulnerability in Oracle Access Manager allows low privileged attackers to achieve a full system takeover.

Vulnerability

This is an easily exploitable flaw within the Authentication Engine that requires the attacker to have low privileges and network access via HTTP. The vulnerability permits unauthorized takeover of the affected component.

Business impact

Successful exploitation of this vulnerability results in a complete compromise of the Oracle Access Manager instance. Given the CVSS score of 8.8, this poses a high risk to business operations, as attackers could intercept credentials, bypass authentication mechanisms, or manipulate identity management workflows, leading to significant unauthorized access across the enterprise environment.

Remediation

Immediate Action: Apply the relevant security updates provided in the August 2026 Oracle Critical Patch Update.

Proactive Monitoring: Monitor network traffic for unusual HTTP requests targeting the Authentication Engine and review authentication logs for patterns indicating unauthorized privilege escalation.

Compensating Controls: Implement Web Application Firewall (WAF) rules to filter malicious traffic and restrict network access to the Authentication Engine to trusted internal subnets.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a significant risk to identity security and requires immediate attention. Organizations should prioritize patching the identified versions of Oracle Access Manager to prevent potential system takeover and unauthorized access to protected resources.

More Oracle CVEs