Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper authentication flaw in Oracle Access Manager’s Authentication Engine allows an unauthenticated attacker who can reach the exposed HTTP interface to send specially crafted requests. The vulnerability is a classic authentication bypass (CWE‑287) that, when successfully exploited, can compromise the entire access management component, jeopardizing confidentiality, integrity, and availability of all authentication services it protects.

Affected Systems

Affected releases are Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0, components of Oracle Fusion Middleware and typically deployed in enterprise identity and access management stacks.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 indicates high severity. The EPSS score is less than 1%, implying an extremely low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. An attacker only needs network reach to the authentication engine’s HTTP endpoint; no credentials or privileged access are required. Successful exploitation results in full control of the Access Manager instance and potentially compromise downstream services that rely on it.

Generated by OpenCVE AI on August 2, 2026 at 22:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Critical Patch Update July 2026 that fixes the authentication bypass in Oracle Access Manager.
  • Restrict external network access to the Authentication Engine’s HTTP interface using firewall rules or VPN access controls.
  • Enable detailed logging and monitor for repeated authentication attempts or unauthorized requests to detect potential exploitation attempts.

Generated by OpenCVE AI on August 2, 2026 at 22:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Authentication Bypass in Oracle Access Manager Allowing System Takeover

Tue, 28 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Oracle Access Manager Takeover

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Oracle Access Manager Takeover
Weaknesses CWE-287

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle access Manager
CPEs cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle access Manager
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Access Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:57:12.332Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60416

cve-icon Vulnrichment

Updated: 2026-07-24T16:05:17.847Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:30:04Z

Weaknesses