CVE-2026-73941
moderateUnauthenticated data access flaw in Oracle Access Manager 12.2.1.4.0 / 14.1.2.1.0
CVE-2026-73941 is a high-severity vulnerability in the Authentication Engine component of Oracle Access Manager (OAM), part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It is easily exploitable by an unauthenticated remote attacker with network access to an OAM server over HTTP, requiring no privileges or user interaction (CVSS 3.1: 8.6, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N). Successful attacks result in unauthorized access to critical data or complete access to all OAM-accessible data — a confidentiality-only impact — and because the vulnerability has a scope change, attacks may significantly impact additional products beyond OAM itself. Organizations running the affected OAM versions as their single sign-on/authentication layer are at risk of broad data exposure across everything OAM protects. No public proof of concept is known and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, so there is currently no evidence of in-the-wild exploitation.
What to do: Apply Oracle's Critical Patch Update that remedies this CVE to all OAM installations on 12.2.1.4.0 and 14.1.2.1.0 as soon as it is available. Until patched, restrict HTTP(S) reachability of OAM authentication endpoints (VPN or IP allowlisting, deny-by-default at the edge) and monitor logs for anomalous unauthenticated requests against the Authentication Engine. Audit OAM-protected applications for signs of unauthorized data access and rotate credentials, sessions, and tokens if compromise is suspected.
| Oracle Access Manager (Oracle Fusion Middleware, Authentication Engine component) | 12.2.1.4.0, 14.1.2.1.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.