CVE-2026-73947
9.8Oracle · Oracle Access Manager
A critical vulnerability in the Oracle Access Manager Authentication Engine allows unauthenticated remote attackers to achieve full system takeover via HTTP.
Executive summary
An unauthenticated remote attacker can achieve full takeover of Oracle Access Manager, posing a critical risk to identity and access infrastructure.
Vulnerability
This is a critical flaw within the Authentication Engine component that permits an unauthenticated attacker, with network access via HTTP, to gain complete control over the application. The vulnerability is highly accessible as it requires no user interaction or prior authentication to exploit.
Business impact
The ability for an unauthenticated attacker to take over the Oracle Access Manager platform presents a catastrophic risk to organizational security. Successful exploitation allows for total compromise of confidentiality, integrity, and availability, potentially granting attackers access to all downstream applications managed by this identity provider. Given the CVSS score of 9.8, this vulnerability must be treated as a highest-priority security event.
Remediation
Immediate Action: Review the official Oracle Security Alert at the provided reference link and apply the necessary patches or configuration changes as soon as they become available.
Proactive Monitoring: Monitor network traffic for unusual HTTP requests targeting the Authentication Engine and review system logs for signs of unauthorized administrative access or unexpected account creation.
Compensating Controls: Implement strict network segmentation and ensure the Oracle Access Manager interface is not exposed to the public internet, using a Web Application Firewall to filter suspicious HTTP traffic.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Due to the critical nature of this vulnerability and the potential for total system compromise, organizations running the affected versions of Oracle Access Manager should prioritize this as an emergency patching task. If immediate patching is not possible, ensure that the service is isolated from untrusted networks until a vendor-supplied update is verified and deployed.
More Oracle CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
- Oracle Advisory Vendor advisory