CVE-2026-60726
8.8Oracle · Oracle Access Manager
A vulnerability in the Authentication Engine of Oracle Access Manager allows a low privileged attacker with network access via HTTP to compromise the system.
Executive summary
A critical vulnerability in Oracle Access Manager allows low privileged attackers to achieve a full system takeover.
Vulnerability
This is an easily exploitable flaw within the Authentication Engine that requires the attacker to have low privileges and network access via HTTP. The vulnerability permits unauthorized takeover of the affected component.
Business impact
Successful exploitation of this vulnerability results in a complete compromise of the Oracle Access Manager instance. Given the CVSS score of 8.8, this poses a high risk to business operations, as attackers could intercept credentials, bypass authentication mechanisms, or manipulate identity management workflows, leading to significant unauthorized access across the enterprise environment.
Remediation
Immediate Action: Apply the relevant security updates provided in the August 2026 Oracle Critical Patch Update.
Proactive Monitoring: Monitor network traffic for unusual HTTP requests targeting the Authentication Engine and review authentication logs for patterns indicating unauthorized privilege escalation.
Compensating Controls: Implement Web Application Firewall (WAF) rules to filter malicious traffic and restrict network access to the Authentication Engine to trusted internal subnets.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a significant risk to identity security and requires immediate attention. Organizations should prioritize patching the identified versions of Oracle Access Manager to prevent potential system takeover and unauthorized access to protected resources.