Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Access Manager accessible data as well as unauthorized read access to a subset of Oracle Access Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Access Manager’s Authentication Engine contains a flaw that enables an unauthenticated attacker with HTTP network access to compromise the service. Successful exploitation requires an attacker to initiate the request and rely on a human actor who is not the attacker to perform a completing step, after which the attacker can insert, update, or delete data that the Access Manager protects and read a subset of the data it safeguards. This results in both integrity compromise and limited confidentiality loss for affected data.

Affected Systems

The vulnerability affects Oracle Access Manager version 12.2.1.4.0 and 14.1.2.1.0. It is present in the Authentication Engine component.

Risk and Exploitability

The CVSS 3.1 base score is 6.1, indicating a moderate severity with low confidentiality (L) and integrity (L) impact. The EPSS score is below 1 %, reflecting a low probability of exploitation. It is not listed in CISA’s KEV catalog. The attack vector requires remote HTTP access, a human collaborator, and yet remains a significant threat because it can lead to unauthorized data modification and disclosure if the attack succeeds.

Generated by OpenCVE AI on August 5, 2026 at 02:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch for Oracle Access Manager released in the CPU Jul 2026 update that fixes the Authentication Engine flaw.
  • Limit HTTP exposure to the Access Manager instance by configuring firewalls or network ACLs to allow traffic only from trusted internal IP ranges.
  • Enforce multi‑factor authentication for all administrative and privileged actions within Oracle Access Manager.

Generated by OpenCVE AI on August 5, 2026 at 02:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability in Oracle Access Manager Authentication Engine

Sat, 01 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability in Oracle Access Manager Authentication Engine

Tue, 28 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-Based Authorization Flaw in Oracle Access Manager Allows Unauthorized Data Modification and Disclosure
Weaknesses CWE-287
CWE-523

Fri, 24 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-Based Authorization Flaw in Oracle Access Manager Allows Unauthorized Data Modification and Disclosure
Weaknesses CWE-287
CWE-523

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Access Manager accessible data as well as unauthorized read access to a subset of Oracle Access Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle access Manager
CPEs cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle access Manager
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Access Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:05:22.751Z

Reserved: 2026-07-08T15:51:40.514Z

Link: CVE-2026-60146

cve-icon Vulnrichment

Updated: 2026-07-23T16:13:45.866Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:15:03Z

Weaknesses