CVE-2026-73950

9.8

Oracle · Access Manager

A critical vulnerability in the Oracle Access Manager Authentication Engine allows an unauthenticated attacker to achieve a full system takeover via network access.

Executive summary

A critical, unauthenticated remote code execution vulnerability in Oracle Access Manager enables complete system takeover, posing an extreme risk to organizational infrastructure.

Vulnerability

The vulnerability resides in the Authentication Engine of Oracle Access Manager, where an unauthenticated attacker can leverage HTTP requests to bypass security controls and gain full control over the application.

Business impact

The CVSS score of 9.8 confirms this as a critical severity issue that could lead to complete loss of confidentiality, integrity, and availability. A successful compromise would allow an attacker to gain administrative control over identity and access management functions, potentially enabling lateral movement across the enterprise and unauthorized access to sensitive corporate data.

Remediation

Immediate Action: Review the latest Oracle security alerts at the provided vendor reference link to identify and apply the specific patch or update version required for your deployment.

Proactive Monitoring: Monitor network traffic and authentication logs for anomalous HTTP requests directed at the Authentication Engine, specifically looking for unexpected payloads or unauthorized access patterns.

Compensating Controls: Implement strict network segmentation and restrict access to the Oracle Access Manager management interfaces via a Web Application Firewall (WAF) to block suspicious inbound traffic.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical CVSS score of 9.8 and the potential for total system compromise, this vulnerability should be treated as a top priority for remediation. Administrators must identify impacted instances immediately and apply the vendor-provided patches as soon as they are available to prevent unauthorized access and potential data breaches.

More Oracle CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources