CVE-2026-73947

9.8

Oracle · Oracle Access Manager

A critical vulnerability in the Oracle Access Manager Authentication Engine allows unauthenticated remote attackers to achieve full system takeover via HTTP.

Executive summary

An unauthenticated remote attacker can achieve full takeover of Oracle Access Manager, posing a critical risk to identity and access infrastructure.

Vulnerability

This is a critical flaw within the Authentication Engine component that permits an unauthenticated attacker, with network access via HTTP, to gain complete control over the application. The vulnerability is highly accessible as it requires no user interaction or prior authentication to exploit.

Business impact

The ability for an unauthenticated attacker to take over the Oracle Access Manager platform presents a catastrophic risk to organizational security. Successful exploitation allows for total compromise of confidentiality, integrity, and availability, potentially granting attackers access to all downstream applications managed by this identity provider. Given the CVSS score of 9.8, this vulnerability must be treated as a highest-priority security event.

Remediation

Immediate Action: Review the official Oracle Security Alert at the provided reference link and apply the necessary patches or configuration changes as soon as they become available.

Proactive Monitoring: Monitor network traffic for unusual HTTP requests targeting the Authentication Engine and review system logs for signs of unauthorized administrative access or unexpected account creation.

Compensating Controls: Implement strict network segmentation and ensure the Oracle Access Manager interface is not exposed to the public internet, using a Web Application Firewall to filter suspicious HTTP traffic.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the critical nature of this vulnerability and the potential for total system compromise, organizations running the affected versions of Oracle Access Manager should prioritize this as an emergency patching task. If immediate patching is not possible, ensure that the service is isolated from untrusted networks until a vendor-supplied update is verified and deployed.

More Oracle CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources