Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass and System Takeover
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Authentication Engine of Oracle Access Manager allows a low‑privileged attacker who can reach the system over HTTP to compromise the OAM instance. This could enable configuration changes, data exfiltration and lateral movement to other Fusion Middleware products. The description states the vulnerability is "easily exploitable" and "allows takeover", so it is inferred that an attacker with network access could succeed quickly, but the exact timeline is not explicitly provided.

Affected Systems

Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 are affected. These releases are part of the Oracle Fusion Middleware stack and provide authentication and access control for enterprise applications.

Risk and Exploitability

The CVSS 3.1 Base Score of 9.9 indicates severe impacts on confidentiality, integrity and availability. The EPSS score of less than 1% suggests that exploitation activity is currently low. The vulnerability is remotely exploitable via HTTP with low‑privilege credentials, and the scope change noted in the description indicates that exploitation could affect additional Oracle products beyond the Access Manager itself.

Generated by OpenCVE AI on September 17, 2026 at 06:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Access Manager security patch or upgrade to a supported, non‑affected release
  • Restrict HTTP access to the OAM instance to trusted networks or IP addresses
  • Enable audit logging and monitor for suspicious authentication activity

Generated by OpenCVE AI on September 17, 2026 at 06:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Remote Authentication Bypass Leading to Oracle Access Manager Takeover

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle access Manager
CPEs cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle access Manager
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Access Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:30:13.659Z

Reserved: 2026-08-13T18:41:45.892Z

Link: CVE-2026-73945

cve-icon Vulnrichment

Updated: 2026-09-16T14:53:59.139Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:45.563

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-73945

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T06:15:04Z

Weaknesses