CVE-2026-71163
9.9Oracle · Oracle Access Manager
A critical authentication engine vulnerability in Oracle Access Manager allows low privileged network attackers to compromise the system and impact additional products via scope change.
Executive summary
A critical vulnerability in Oracle Access Manager allows low privileged attackers to gain unauthorized access to data and perform unauthorized modifications, necessitating immediate attention.
Vulnerability
This vulnerability resides in the Authentication Engine component of Oracle Access Manager and allows an authenticated user with low privileges to leverage network access for unauthorized data manipulation, access, and partial denial of service. The flaw facilitates a scope change, meaning the impact extends beyond the immediate application to potentially compromise integrated systems.
Business impact
The CVSS 3.1 score of 9.9 underscores the extreme severity of this flaw, as it permits full unauthorized access to critical data and potential compromise of connected middleware systems. A successful exploit could lead to complete loss of data confidentiality and integrity, resulting in significant operational disruption, regulatory non-compliance, and severe reputational damage.
Remediation
Immediate Action: Review the latest Oracle security alerts at the provided reference and apply the corresponding security patch or configuration update as soon as it becomes available.
Proactive Monitoring: Implement enhanced logging and monitoring for the Authentication Engine, specifically focusing on anomalous HTTP requests or modifications to sensitive user and policy data.
Compensating Controls: Deploy or tune Web Application Firewall (WAF) rules to inspect and block suspicious traffic patterns targeting the Oracle Access Manager authentication endpoints.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical CVSS 9.9 rating and the potential for wide-reaching impact across the Oracle Fusion Middleware stack, organizations must prioritize the identification of affected Oracle Access Manager instances. Administrators should monitor official Oracle security channels for the release of the remediation patch and be prepared to deploy it immediately upon availability to prevent unauthorized access or system compromise.
More Oracle CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
- Oracle Advisory Vendor advisory