Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Unauthorized Access and Potential System Takeover
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Authentication Engine component of Oracle Access Manager allows a low‑privileged attacker with network access via HTTP to bypass normal authentication controls. This enables unauthorized use of the system and can lead to full takeover of the Access Manager instance. The weakness is rooted in improper access control (CWE-284), resulting in complete compromise of confidentiality, integrity, and availability for the affected application.

Affected Systems

Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 are vulnerable. These releases are the only ones identified as impacted by the advisory.

Risk and Exploitability

The CVSS v3.1 base score of 8.5 indicates high severity. The EPSS score of less than 1% implies the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, a successful exploit can result in total takeover of the Access Manager system and may affect other Oracle Fusion Middleware products due to a scope change. The attack vector is remote over an HTTP connection, requiring only low privileges, which increases the potential attack surface.

Generated by OpenCVE AI on September 20, 2026 at 12:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle‑published security patch that addresses the authentication engine bypass for Access Manager versions 12.2.1.4.0 and 14.1.2.1.0.
  • Restrict HTTP traffic to the Access Manager service by configuring firewalls or reverse proxies to allow only trusted IP ranges, reducing exposure to potential attackers.
  • Review and enforce strict role‑based access controls in the Access Manager configuration to ensure low‑privileged users cannot elevate privileges or access protected resources.

Generated by OpenCVE AI on September 20, 2026 at 12:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Title Authentication Engine Access Control Bypass Allowing System Takeover

Sun, 20 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Oracle Access Manager Authentication Engine Bypass Enables System Takeover
Weaknesses CWE-863

Thu, 17 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Oracle Access Manager Authentication Engine Bypass Enables System Takeover
Weaknesses CWE-863

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle access Manager
CPEs cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle access Manager
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Access Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:28:10.055Z

Reserved: 2026-08-31T15:40:57.329Z

Link: CVE-2026-83002

cve-icon Vulnrichment

Updated: 2026-09-16T14:54:44.509Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:06.790

Modified: 2026-09-21T18:07:42.833

Link: CVE-2026-83002

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T12:45:17Z

Weaknesses