Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Privilege Escalation and Takeover of Oracle Access Manager
Action: Immediate Patch
AI Analysis

Impact

Oracle Access Manager’s Authentication Engine contains a broken access control flaw (CWE-284) that permits an attacker with network reachability over HTTP to gain full administrative control. The vulnerability enables a high‑privileged attacker to fully compromise the component, allowing arbitrary configuration changes, data exfiltration, and service disruption. The formal description states that successful exploitation can result in a complete takeover of Oracle Access Manager, exposing confidential data and impacting the confidentiality, integrity, and availability of the system.

Affected Systems

Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 are vulnerable. No other versions are affected according to the advisory, and upgrades beyond these releases include the fix. The flaw’s scope change indicates that compromise of the Authentication Engine could also affect other Oracle Fusion Middleware products in the environment.

Risk and Exploitability

The CVSS 3.1 base score of 9.1 categorizes this as a critical vulnerability. The EPSS score of less than 1% suggests a low likelihood of exploitation, and the flaw is not currently listed in CISA’s KEV catalog. Nevertheless, the advisory labels it as easily exploitable, implying minimal preparation is required. Attackers would need network access to the HTTP interface and high‑privilege credentials or the ability to forge them, after which they can gain full control of the Authentication Engine and potentially affect other connected components.

Generated by OpenCVE AI on September 17, 2026 at 05:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch or upgrade to a fixed release of Oracle Access Manager, following Oracle’s recommendation for versions 12.2.1.4.0 and 14.1.2.1.0.
  • Limit HTTP access to the Authentication Engine to trusted administrators only, for example by implementing firewall rules or a VPN tunnel to reduce the attack surface.
  • Enforce robust authentication controls and disable any unused authentication methods to diminish available attack vectors.

Generated by OpenCVE AI on September 17, 2026 at 05:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Oracle Access Manager Authentication Engine Broken Access Control Vulnerability Allowing Remote Takeover

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle access Manager
CPEs cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle access Manager
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Access Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:30:07.593Z

Reserved: 2026-08-13T18:41:45.892Z

Link: CVE-2026-73946

cve-icon Vulnrichment

Updated: 2026-09-16T14:54:02.751Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:45.670

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-73946

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T06:00:09Z

Weaknesses