ZeroHour

CVE-2026-71163

large

Critical Flaw in Oracle Access Manager Authentication Engine Enables Full Compromise

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-71163 is a critical (CVSS 9.9) vulnerability in the Authentication Engine component of Oracle Access Manager, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It is easily exploitable by a low-privileged (i.e., authenticated but unprivileged) attacker with network access to the OAM service over HTTP, requiring no user interaction. Because the CVSS scope is changed, successful attacks on OAM can also significantly impact additional products beyond Oracle Access Manager itself. A successful exploit grants unauthorized creation, deletion, or modification of critical OAM-accessible data, full read access to that data, and the ability to cause a partial denial of service. No public proof of concept is known and the flaw is not on the CISA KEV list, so there is no evidence of in-the-wild exploitation, but internet-facing OAM deployments remain high-value targets.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-71163 to all OAM 12.2.1.4.0 and 14.1.2.1.0 installations as soon as possible, prioritizing internet-facing instances. Until patched, restrict HTTP access to OAM endpoints (VPN/IP allowlisting), enforce MFA and least-privilege for all accounts that can reach OAM, and monitor OAM logs for anomalous data modification or availability degradation. Inventory Fusion Middleware deployments to confirm no unpatched 12.2.1.4.0 or 14.1.2.1.0 OAM servers remain.

Affected
Oracle Access Manager (Oracle Fusion Middleware, Authentication Engine component)
Estimated exposure
large≈10,000–30,000 internet-exposed OAM servers, plus many more internal enterprise deployments serving millions of downstream SSO users — Oracle Access Manager is enterprise SSO middleware whose login endpoints are routinely indexed by public internet scans (e.g., Shodan) in the low tens of thousands, with additional instances behind corporate firewalls.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Access Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Access Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Access Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.