Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution / Full System Compromise
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is an authentication bypass that allows an unauthenticated attacker to compromise Oracle Access Manager. The weakness, identified as CWE‑287 and CWE‑306, permits attackers to gain full control of the system, providing the attacker with confidentiality, integrity, and availability impacts. Successful exploitation can lead to complete takeover of the Oracle Access Manager instance and the data it protects.

Affected Systems

Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0, components of Oracle Fusion Middleware. Only these releases are affected; other versions are not impacted.

Risk and Exploitability

The vulnerability scores a CVSS 3.1 base score of 9.8, indicating a critical risk. The EPSS score is less than 1 percent, suggesting a low current exploitation probability, but the absence of the vulnerability from the CISA KEV catalog does not reduce its severity. Attackers can exploit it remotely over network protocols T3 and IIOP, requiring no authentication. Given the high severity and the possibility of remote compromise, the risk is significant for vulnerable environments.

Generated by OpenCVE AI on September 17, 2026 at 05:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Access Manager patch that addresses the authentication bypass.
  • If a patch is not yet available, upgrade to a version that is not listed as affected by the vulnerability.
  • Disable the T3 and IIOP protocols on the Oracle Access Manager host if they are not required for your business operations.

Generated by OpenCVE AI on September 17, 2026 at 05:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Attack Compromises Oracle Access Manager via T3/IIOP

Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-306

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle access Manager
CPEs cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle access Manager
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Access Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T22:54:39.639Z

Reserved: 2026-08-13T18:41:45.892Z

Link: CVE-2026-73940

cve-icon Vulnrichment

Updated: 2026-09-15T22:46:38.802Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:44.943

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-73940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T05:45:18Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function