Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Access Manager executes to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Oracle Access Manager Authentication Engine allows an attacker with low local privileges and access to the physical network segment that the hardware runs on to compromise the product. The vulnerability exploits a weakness in authentication (CWE‑287). Successful exploitation can result in a complete takeover of Oracle Access Manager, with severe confidentiality, integrity, and availability impacts at score 8.0.

Affected Systems

The affected products are Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0, part of Oracle Fusion Middleware. Systems running these versions are at risk if a low‑privileged attacker can connect to the same local network segment as the Oracle Access Manager hardware.

Risk and Exploitability

The CVSS score of 8.0 and an EPSS score of <1% suggest that overall exploitation likelihood is low, yet the vector AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H indicates that the flaw can be exploited from a local network with minimal privileges and no user interaction. It is not listed in CISA KEV. The likely attack vector is a low‑privileged attacker on the same physical network who can reach the Oracle Access Manager instance. Successful exploitation would result in a takeover of Oracle Access Manager.

Generated by OpenCVE AI on August 2, 2026 at 20:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch that addresses CVE-2026-61067 to all Oracle Access Manager installations 12.2.1.4.0 and 14.1.2.1.0.
  • Restrict physical and network access to the hardware on which Oracle Access Manager runs, limiting connectivity to trusted personnel only to reduce attack surface.
  • Implement strict authentication and least privilege controls for local users to counter the CWE‑287 authentication flaw, and enable logging to detect unauthorized access.

Generated by OpenCVE AI on August 2, 2026 at 20:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Local Network Authentication Bypass Leading to Full Oracle Access Manager Takeover

Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Local Network Attack Enables Complete Takeover of Oracle Access Manager
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local Network Attack Enables Complete Takeover of Oracle Access Manager
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Access Manager executes to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle access Manager
CPEs cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle access Manager
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Access Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:57:16.147Z

Reserved: 2026-07-08T15:51:55.611Z

Link: CVE-2026-61067

cve-icon Vulnrichment

Updated: 2026-07-24T14:18:28.985Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:37.423

Modified: 2026-07-28T05:17:16.317

Link: CVE-2026-61067

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:15:13Z

Weaknesses