CVE-2026-73945
9.9Oracle · Oracle Access Manager
An authentication engine vulnerability in Oracle Access Manager allows low privileged network attackers to achieve a full system takeover.
Executive summary
A critical vulnerability in Oracle Access Manager allows low privileged attackers to gain complete control over the system and potentially impact integrated products.
Vulnerability
This vulnerability affects the Authentication Engine component of Oracle Access Manager, allowing an attacker with low privileges and network access via HTTP to compromise the application. The flaw permits a scope change, meaning exploitation can lead to the takeover of the Access Manager and negatively affect other products within the Fusion Middleware environment.
Business impact
The CVSS base score of 9.9 underscores the extreme severity of this flaw, as it represents a near-total compromise of the system's Confidentiality, Integrity, and Availability. Because Oracle Access Manager is typically a central component for identity and access, a successful compromise could allow an attacker to bypass security controls across the entire enterprise, leading to unauthorized access to sensitive data and severe operational disruption.
Remediation
Immediate Action: Review the official Oracle Security Alert referenced in the advisory to identify and apply the necessary security patches for versions 12.2.1.4.0 and 14.1.2.1.0.
Proactive Monitoring: Audit application access logs for unusual administrative activity or repeated authentication attempts originating from low privileged accounts.
Compensating Controls: Implement strict network segmentation to restrict access to the Oracle Access Manager management interface and deploy WAF rules to detect and block malicious HTTP requests targeting authentication endpoints.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a critical risk to the security infrastructure of any organization utilizing the affected versions of Oracle Access Manager. IT and security teams should prioritize the identification of these versions within their environment and apply vendor-supplied patches immediately upon release. Failure to remediate this flaw could grant an attacker persistent and elevated access to the broader corporate network.
More Oracle CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
- Oracle Advisory Vendor advisory