Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authorization Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Access Manager. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-08-18
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper authorization weakness in Oracle Access Manager’s Authorization Engine permits a local or remote attacker with low‑privileged credentials to send specially crafted TCP requests that exhaust resources or otherwise render the component unavailable. The vulnerability is exploitable without user interaction and provides direct damage to availability, as reflected in the CVSS v3.1 score of 4.3 and the single impact category of availability.

Affected Systems

The flaw affects Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0, both delivered as part of Oracle Fusion Middleware.

Risk and Exploitability

The EPSS score of less than 1% indicates that the vulnerability has a very low probability of being seen in the wild, and it is not listed in CISA's KEV catalog. Nevertheless, the remote attack vector and the lack of required user interaction make it straightforward for an attacker who can reach the exposed ports. Because the attack can result in a partial denial of service, it is recommended that the vulnerability be treated with the same priority as any other availability issue.

Generated by OpenCVE AI on August 20, 2026 at 18:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch referenced in the Oracle Security Alert for CVE‑2026‑71124.
  • Restrict network access to the Oracle Access Manager servers so that only trusted IP addresses or VPN connections can reach the Authorization Engine’s TCP ports.
  • Enable stricter access controls by disabling or limiting low‑privilege accounts that can reach the Authorization Engine, and implement input validation or rate limiting to mitigate resource exhaustion attempts.

Generated by OpenCVE AI on August 20, 2026 at 18:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Authorization Engine Vulnerability Allows Low-Privilege Attacker to Cause Partial Denial of Service

Thu, 20 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Oracle Access Manager Partial Denial of Service Vulnerability

Wed, 19 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Oracle Access Manager Partial Denial of Service Vulnerability

Wed, 19 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service via Low-Privilege Network Access in Oracle Access Manager Authorization Engine
Weaknesses CWE-400

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service via Low-Privilege Network Access in Oracle Access Manager Authorization Engine
Weaknesses CWE-400

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authorization Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Access Manager. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle access Manager
CPEs cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle access Manager
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Oracle Access Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:07.395Z

Reserved: 2026-08-04T22:06:34.618Z

Link: CVE-2026-71124

cve-icon Vulnrichment

Updated: 2026-08-19T12:09:03.911Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:13.177

Modified: 2026-08-20T15:01:49.310

Link: CVE-2026-71124

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T18:30:04Z

Weaknesses