Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability exists in the Authentication Engine component of Oracle Access Manager and allows an unauthenticated attacker that can reach the service over HTTP to compromise the system. An attacker can achieve full system takeover, compromising confidentiality, integrity, and availability. The flaw reflects an improper access control issue (CWE-284) that permits bypass of authentication checks.

Affected Systems

Affected vendors/products: Oracle Corporation's Oracle Access Manager as part of Oracle Fusion Middleware. Supported releases 12.2.1.4.0 and 14.1.2.0.0 are affected. No other versions were identified at the time of this advisory.

Risk and Exploitability

The CVSS v3.1 base score severe impact, yet the EPSS score of less than 1 % indicates a low probability of widespread exploitation. The vulnerability is not yet catalogued in the CISA KEV listing. Exploitation would require the attacker to successfully reach the authentication engine via the public HTTP interface without valid credentials, then exploit the access control flaw to gain administrative control. Because the attack path is relatively simple and the damage is total takeover, the threat remains significant for exposed installations.

Generated by OpenCVE AI on September 17, 2026 at 05:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch that fixes the authentication engine flaw or upgrade to a later, of Oracle Access Manager.
  • Restrict network access to the Oracle Access Manager service to trusted hosts only; consider disabling the public HTTP endpoint or protecting it behind VPN or firewall rules.
  • Implement strict audit logging for authentication events and monitor logs for anomalous activity such as repeated unauthenticated requests; enable intrusion detection targeting attempts against the authentication engine.
  • Enforce role‑based access controls within the application to ensure that even if an attacker gains a session, normal privilege levels cannot lead to full takeover; review and harden all access control configurations.

Generated by OpenCVE AI on September 17, 2026 at 05:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle access Manager
CPEs cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:access_manager:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle access Manager
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Access Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:29:22.451Z

Reserved: 2026-08-13T18:41:45.893Z

Link: CVE-2026-73958

cve-icon Vulnrichment

Updated: 2026-09-16T14:54:19.204Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:46.993

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-73958

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T06:00:09Z

Weaknesses