Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-06-16
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Authentication Engine component of Oracle Access Manager permits a low‑privileged attacker who can reach the server over HTTP to compromise the system. Exploitation can result in a complete takeover of Oracle Access Manager, giving the attacker full control and enabling further attacks against other products that rely on it. The impact is full compromise of confidentiality, integrity and availability.

Affected Systems

Oracle Corporation’s Oracle Access Manager, part of Oracle Fusion Middleware, is affected. Versions 12.2.1.4.0 and 14.1.2.1.0 are vulnerable. No specific patch or workaround is listed by the vendor in the provided data.

Risk and Exploitability

The vulnerability has a CVSS 3.1 Base Score of 9.9, indicating critical severity. The EPSS score is less than 1 %, suggesting low but non‑zero exploitation probability. It is not yet in the CISA KEV catalog. The attack vector is inferred to be over the network via HTTP, with low privileged permissions required—a typical remote code execution scenario that can be executed from any machine with network access to the target. Successful exploitation leads to full system takeover, making the risk extremely high for any exposed instances.

Generated by OpenCVE AI on June 17, 2026 at 20:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Access Manager patch or upgrade to a non‑vulnerable version for both 12.2.1.4.0 and 14.1.2.1.0
  • Restrict HTTP access to the Authentication Engine by configuring firewalls or network segmentation to allow only trusted networks or IP ranges
  • Enforce stronger authentication, such as multi‑factor authentication, and limit user privileges to the minimum required for operational roles

Generated by OpenCVE AI on June 17, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle access Manager
CPEs cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle access Manager
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Access Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T15:37:40.758Z

Reserved: 2026-04-01T20:03:40.837Z

Link: CVE-2026-35313

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T23:00:05Z

Weaknesses

No weakness.