Unauthenticated Takeover Flaw in Oracle Access Manager Authentication Engine (CVSS 10.0)
AI analysis
CVE-2026-71133 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager (OAM), part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction, and successful attacks result in complete takeover of Oracle Access Manager. Because the CVSS vector includes a scope change (S:C), compromise of OAM can significantly impact additional products beyond the vulnerable component itself. Any organization exposing an affected OAM deployment — which commonly fronts internet-facing single sign-on and authentication portals — is at risk of full confidentiality, integrity, and availability impact. No public proof of concept is known and the flaw is not on the CISA KEV list, but the unauthenticated, network-exploitable nature makes patching urgent.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-71133 to affected OAM 12.2.1.4.0 and 14.1.2.1.0 deployments as an emergency change, prioritizing any instance reachable from the internet. Until patched, restrict network access to OAM authentication endpoints (VPNs, IP allowlists, WAF rules) and enforce TLS so the HTTP attack path is closed. Review OAM and federation logs for unauthenticated anomalous requests or unexpected administrative changes that could indicate attempted compromise.
Affected
| Oracle Access Manager (Oracle Fusion Middleware, Authentication Engine component) | 12.2.1.4.0, 14.1.2.1.0 |
Estimated exposure
large≈10,000–50,000 internet-exposed OAM instances across thousands of enterprise organizations (estimate) — Oracle does not publish install counts, but OAM is enterprise IAM software that is intentionally internet-facing for SSO, and internet-wide scans typically fingerprint tens of thousands of exposed OAM login endpoints.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).