Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Authentication Engine component of Oracle Access Manager permits an attacker with limited privileges who can reach the system via HTTP to compromise the service. Successful exploitation can lead to full control of the Access Manager, resulting in loss of confidentiality, integrity, and availability of the authentication infrastructure. The description indicates that normal credential checks may be bypassed; however, this inference is not explicitly confirmed in the provided data.

Affected Systems

The issue affects Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0. Any environment deploying either of these releases is vulnerable unless mitigated or patched.

Risk and Exploitability

A CVSS v3.1 score of 8.8 reflects high severity, and the entry is not listed in CISA's KEV catalog. The EPSS score is < 1%, but the vulnerability description indicates that it is easily exploitable over the network via HTTP. Given the low attack effort and the potential for a complete service takeover, the risk should be treated as high.

Generated by OpenCVE AI on August 21, 2026 at 15:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Access Manager security patch or upgrade to a non‑vulnerable release
  • Restrict network exposure of the Access Manager by placing it behind a firewall and limiting HTTP access to trusted hosts
  • Enforce strong authentication and periodic security reviews to prevent unauthorized access

Generated by OpenCVE AI on August 21, 2026 at 15:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Oracle Access Manager Remote Takeover via Low-Privilege HTTP Attack

Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle access Manager
CPEs cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle access Manager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Access Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T17:54:54.279Z

Reserved: 2026-07-08T15:51:55.583Z

Link: CVE-2026-60726

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:40.500

Modified: 2026-08-20T15:18:42.933

Link: CVE-2026-60726

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T15:45:18Z

Weaknesses