CVE-2026-73940
9.8Oracle · Oracle Access Manager
Oracle Access Manager contains an easily exploitable vulnerability in the Authentication Engine allowing unauthenticated remote attackers to achieve full system takeover via T3 or IIOP protocols.
Executive summary
An unauthenticated remote code execution vulnerability in Oracle Access Manager allows attackers to gain complete control over the affected system.
Vulnerability
The Authentication Engine within Oracle Access Manager is susceptible to an unauthenticated remote exploit. Attackers can leverage the T3 or IIOP protocols to compromise the application, leading to a complete system takeover.
Business impact
This vulnerability carries a CVSS base score of 9.8, indicating a critical risk to business operations. A successful compromise grants an attacker full control over the identity management infrastructure, potentially leading to unauthorized access to sensitive corporate data, lateral movement within the network, and complete service disruption.
Remediation
Immediate Action: Review the official Oracle security advisory at the link provided in the references section and apply the necessary patches as soon as they become available.
Proactive Monitoring: Monitor network traffic for anomalous activity involving the T3 and IIOP protocols, and audit Oracle Access Manager logs for signs of unauthorized authentication attempts.
Compensating Controls: Restrict network access to the Oracle Access Manager instance to trusted IP addresses only, and implement strict egress filtering to prevent unauthorized communication from the server to external networks.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical nature of this flaw and its potential for complete system compromise, organizations should prioritize the identification and patching of all Oracle Access Manager instances. Until patches are applied, ensure that access to affected components is strictly restricted via network segmentation to minimize the attack surface.
More Oracle CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
- Oracle Advisory Vendor advisory