Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Unauthorized Access and Potential System Takeover
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Authentication Engine component of Oracle Access Manager allows a low‑privileged attacker with network access via HTTP to compromise the system. The vulnerability can be exploited to obtain full control of the application, which in turn can affect other Oracle Fusion Middleware products due to a scope change. Successful exploitation leads to loss of confidentiality, integrity, and availability of the protected resources.

Affected Systems

Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 are vulnerable. These are the only released releases identified as impacted by the advisory.

Risk and Exploitability

The CVSS v3.1 base score of 8.5 indicates high severity. The EPSS score of less than 1% implies that the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the theoretical impact of a successful attack—complete takeover of the Access Manager system—warrants prompt remediation. The attack vector appears to be remote over an HTTP connection, and the flaw likely involves improper access control, allowing a low‑privileged user to bypass authentication checks.

Generated by OpenCVE AI on September 17, 2026 at 04:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle-published patch for versions 12.2.1.4.0 and 14.1.2.1.0 as soon as it becomes available.
  • Configure network controls (e.g., firewall rules or reverse proxy) to restrict HTTP access to trusted IP ranges only for the Oracle Access Manager service.
  • Review and tighten authentication and authorization settings in the Access Manager configuration to enforce strict access controls, ensuring that low‑privileged users cannot elevate privileges or access protected resources.

Generated by OpenCVE AI on September 17, 2026 at 04:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Oracle Access Manager Authentication Engine Bypass Enables System Takeover
Weaknesses CWE-863

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle access Manager
CPEs cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle access Manager
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Access Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:28:10.055Z

Reserved: 2026-08-31T15:40:57.329Z

Link: CVE-2026-83002

cve-icon Vulnrichment

Updated: 2026-09-16T14:54:44.509Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:06.790

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83002

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:45:17Z

Weaknesses