Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Access Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Access Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Access Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).
Published: 2026-09-15
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access and Partial Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is in the Authentication Engine component of Oracle Access Manager and allows an attacker with low privileges and network access via HTTP to compromise the product. An attacker can create, delete, or modify access permissions, gain unauthorized access to critical data, and cause a partial denial of service. The flaw thus leads to high confidentiality and integrity impact and can also affect availability to a limited extent.

Affected Systems

Oracle Access Manager by Oracle Corporation, versions 12.2.1.4.0 and 14.1.2.1.0, are affected. The vulnerability may also impact other Oracle Fusion Middleware components because the authentication engine is used across services, potentially changing the scope of the compromise.

Risk and Exploitability

CVSS base score of 9.9 classifies the issue as critical. The EPSS score of < 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not yet listed in CISA KEV. However, the remote attack vector over HTTP and the requirement of only low privileges make it attractive to attackers. The flaw’s impact includes unauthorized data access, potential manipulation of access controls, and partial service disruption, which collectively pose a severe risk to systems relying on Oracle Access Manager.

Generated by OpenCVE AI on September 17, 2026 at 05:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Access Manager patch that fixes the HTTP authentication engine vulnerability (CVE-2026-71163) available from Oracle’s security update repository.
  • Limit network exposure of the Oracle Access Manager service by restricting inbound HTTP traffic to a secure, known set of trusted IP addresses or by placing it behind an internal firewall or VPN.
  • Implement strict access control and authentication best practices, such as mandatory multi‑factor authentication and strong password policies, on all accounts that can interact with the Access Manager.

Generated by OpenCVE AI on September 17, 2026 at 05:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Attack Causes Unauthorized Access and Partial Denial of Service in Oracle Access Manager

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Access Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Access Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Access Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).
First Time appeared Oracle
Oracle access Manager
CPEs cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle access Manager
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L'}


Subscriptions

Oracle Access Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:30:42.856Z

Reserved: 2026-08-04T22:06:34.621Z

Link: CVE-2026-71163

cve-icon Vulnrichment

Updated: 2026-09-16T14:53:50.967Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:42.490

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-71163

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T06:15:03Z

Weaknesses