Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-09-15
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Critical Data
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Authentication Engine of Oracle Access Manager allows an attacker who can reach the application over HTTP to gain unauthorized access without credentials. The vulnerability permits acquisition of all data that the Access Manager can expose, potentially giving control over authentication services and sensitive information. The weakness is categorized as Improper Access Control.

Affected Systems

Oracle Access Manager product versions 12.2.1.4.0 and 14.1.2.1.0 are affected; any deployment of these versions is subject to the flaw.

Risk and Exploitability

The CVSS 3.1 base score of 8.6 and a Scope Change indicate a high‑impact, cross‑component compromise. The EPSS score of less than 1% suggests that exploitation is currently rare, and the vulnerability is not listed in CISA’s KEV catalogue. An unauthenticated attacker with network access via HTTP can exploit the flaw, gaining unrestricted access to critical data and potentially affecting other connected products.

Generated by OpenCVE AI on September 17, 2026 at 06:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Security Update or newer version of Access Manager as detailed in the official Oracle advisory
  • Use network segmentation or firewall rules to restrict HTTP/HTTPS access to the Access Manager installation to trusted internal IP ranges
  • Configure the Access Manager to require strict authentication and TLS enforcement to mitigate the impact of any remaining undiscovered flaws

Generated by OpenCVE AI on September 17, 2026 at 06:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access in Oracle Access Manager Leading to Unauthorized Data Exposure

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle access Manager
CPEs cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle access Manager
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Access Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:30:31.792Z

Reserved: 2026-08-13T18:41:45.892Z

Link: CVE-2026-73941

cve-icon Vulnrichment

Updated: 2026-09-16T15:10:13.574Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:45.050

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-73941

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T06:15:04Z

Weaknesses