ZeroHour

CVE-2026-71133

large

Unauthenticated Takeover Flaw in Oracle Access Manager Authentication Engine (CVSS 10.0)

CVSS 3.1
10.0 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-71133 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager (OAM), part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction, and successful attacks result in complete takeover of Oracle Access Manager. Because the CVSS vector includes a scope change (S:C), compromise of OAM can significantly impact additional products beyond the vulnerable component itself. Any organization exposing an affected OAM deployment — which commonly fronts internet-facing single sign-on and authentication portals — is at risk of full confidentiality, integrity, and availability impact. No public proof of concept is known and the flaw is not on the CISA KEV list, but the unauthenticated, network-exploitable nature makes patching urgent.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-71133 to affected OAM 12.2.1.4.0 and 14.1.2.1.0 deployments as an emergency change, prioritizing any instance reachable from the internet. Until patched, restrict network access to OAM authentication endpoints (VPNs, IP allowlists, WAF rules) and enforce TLS so the HTTP attack path is closed. Review OAM and federation logs for unauthenticated anomalous requests or unexpected administrative changes that could indicate attempted compromise.

Affected
Oracle Access Manager (Oracle Fusion Middleware, Authentication Engine component)12.2.1.4.0, 14.1.2.1.0
Estimated exposure
large≈10,000–50,000 internet-exposed OAM instances across thousands of enterprise organizations (estimate) — Oracle does not publish install counts, but OAM is enterprise IAM software that is intentionally internet-facing for SSO, and internet-wide scans typically fingerprint tens of thousands of exposed OAM login endpoints.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

Oracle’s September patches put Fusion Middleware back in the hot seat

Oracle's September 2026 CPU ships 673 patches including six CVSS 10.0 flaws in Fusion Middleware and Hyperion, none exploited in the wild.

Oracle's September 2026 Critical Security Patch Update delivers 673 patches across 17 product families, led by E-Business Suite with 159 fixes and Fusion Middleware with 153. Six CVSS 10.0 vulnerabilities in Access Manager, Forms, Internet Directory, Platform Security for Java, WebLogic Server, and Hyperion are remotely exploitable without authentication, and Oracle reports none exploited in the wild. Now patching monthly, Oracle urged immediate deployment and warned that unsupported releases are not tested for these flaws.