ZeroHour

CVE-2026-73940

large

Unauthenticated Takeover of Oracle Access Manager via T3/IIOP (CVSS 9.8)

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

Oracle Access Manager, the SSO and authentication component of Oracle Fusion Middleware, contains a critical flaw in its Authentication Engine that is remotely exploitable without any credentials over the T3 and IIOP protocols. An unauthenticated attacker with network reachability to the affected ports can fully compromise the Access Manager instance, gaining complete control over its confidentiality, integrity, and availability (CVSS 3.1: 9.8). Because OAM sits at the center of enterprise authentication, a takeover could enable session/token forgery, credential harvesting, and downstream access to every application it protects. Affected deployments are those running version 12.2.1.4.0 or 14.1.2.1.0. No public proof-of-concept exists and the flaw is not on the CISA KEV list, so exploitation status is currently none known.

What to do: Apply the Oracle Critical Patch Update covering CVE-2026-73940 to OAM 12.2.1.4.0 and 14.1.2.1.0 as the highest-priority change. Immediately block or restrict T3 and IIOP (typically ports 7001/14001 and related WebLogic-administered channels) at the network edge so only trusted administration hosts can reach them. Review OAM and WebLogic logs for unexpected T3/IIOP connections, deserialization errors, or new admin accounts, and rotate credentials and SSO signing keys if compromise is suspected.

Affected
Oracle Access Manager (Oracle Fusion Middleware, Authentication Engine)12.2.1.4.0
Oracle Access Manager (Oracle Fusion Middleware, Authentication Engine)14.1.2.1.0
Estimated exposure
large≈10,000+ internet-reachable OAM servers, out of a global installed base plausibly in the tens of thousands (order of magnitude: tens of thousands of enterprise… — Oracle Access Manager is enterprise SSO middleware common in large corporate and government networks, and public internet scans (Shodan/Censys fingerprinting of OAM endpoints) have historically shown on the order of tens of thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.