CVE-2026-73926
largePrivilege-Abuse Flaw in Oracle Access Manager Authentication Engine (CVSS 8.7)
CVE-2026-73926 is a high-severity (CVSS 3.1: 8.7) vulnerability in the Authentication Engine component of Oracle Access Manager (OAM), part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. The flaw is easily exploitable over the network via HTTP by an attacker who already holds high privileges, allowing them to fully compromise the Oracle Access Manager instance. Because the vulnerability carries a scope change, successful attacks can also significantly impact additional products beyond OAM itself. The impact is unauthorized creation, deletion, or modification of critical data — or all OAM-accessible data — as well as unauthorized read access to critical or all OAM-accessible data (high confidentiality and integrity impact, no availability impact). Organizations running OAM as their web SSO/identity enforcement point are affected; no public proof of concept exists and the CVE is not on the CISA KEV list, so no exploitation is currently known.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-73926 to OAM 12.2.1.4.0 and 14.1.2.1.0 as soon as it is available for your release line. Restrict network access to OAM administrative and internal endpoints so only trusted hosts and VPN ranges can reach them, since exploitation requires a high-privileged HTTP session. Review audit logs for anomalous activity by high-privileged OAM accounts and rotate those credentials if compromise is suspected.
| Oracle Access Manager (Oracle Fusion Middleware, Authentication Engine component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Access Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.