Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Access Manager has an authentication engine flaw that permits an unauthenticated attacker with HTTP network access to compromise the application, potentially allowing full access to all data exposed through Oracle Access Manager. The weakness is an authentication bypass, consistent with CWE‑306, which directly impacts confidentiality, with no integrity or availability impact noted.

Affected Systems

The vulnerability affects Oracle Access Manager, specifically versions 12.2.1.4.0 and 14.1.2.1.0. Because the scope is marked as Changed, other Oracle Fusion Middleware components that interact with Oracle Access Manager may also be impacted.

Risk and Exploitability

The CVSS 3.1 Base Score of 8.6 indicates high severity, and the EPSS score of less than 1% shows that exploitation is currently considered unlikely. The vulnerability is not listed in the CISA KEV catalog. An attacker with network access can trigger the flaw by sending crafted HTTP requests to the Authentication Engine without any authentication or UI interaction, achieving unauthorized access to sensitive data. The overall risk is high severity but low probability of exploitation as of the current EPSS value.

Generated by OpenCVE AI on August 4, 2026 at 04:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Oracle Access Manager security patch that addresses versions 12.2.1.4.0 and 14.1.2.1.0 or upgrade to a version that includes the fix.
  • Restrict inbound network traffic to the Access Manager endpoints by limiting access to trusted IP ranges or implementing firewall rules.
  • Disable or restrict anonymous and default access to the Authentication Engine and review configuration to enforce strong authentication policies.

Generated by OpenCVE AI on August 4, 2026 at 04:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Oracle Access Manager Enables Unauthenticated Data Access

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Oracle Access Manager Enables Unauthenticated Data Access

Wed, 29 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Access in Oracle Access Manager
Weaknesses CWE-287

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Access in Oracle Access Manager
Weaknesses CWE-287

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle access Manager
CPEs cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle access Manager
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Access Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T19:26:40.999Z

Reserved: 2026-07-08T15:51:40.532Z

Link: CVE-2026-60356

cve-icon Vulnrichment

Updated: 2026-07-24T18:37:15.694Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function