ZeroHour

CVE-2026-73941

moderate

Unauthenticated data access flaw in Oracle Access Manager 12.2.1.4.0 / 14.1.2.1.0

CVSS 3.1
8.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-73941 is a high-severity vulnerability in the Authentication Engine component of Oracle Access Manager (OAM), part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It is easily exploitable by an unauthenticated remote attacker with network access to an OAM server over HTTP, requiring no privileges or user interaction (CVSS 3.1: 8.6, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N). Successful attacks result in unauthorized access to critical data or complete access to all OAM-accessible data — a confidentiality-only impact — and because the vulnerability has a scope change, attacks may significantly impact additional products beyond OAM itself. Organizations running the affected OAM versions as their single sign-on/authentication layer are at risk of broad data exposure across everything OAM protects. No public proof of concept is known and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, so there is currently no evidence of in-the-wild exploitation.

What to do: Apply Oracle's Critical Patch Update that remedies this CVE to all OAM installations on 12.2.1.4.0 and 14.1.2.1.0 as soon as it is available. Until patched, restrict HTTP(S) reachability of OAM authentication endpoints (VPN or IP allowlisting, deny-by-default at the edge) and monitor logs for anomalous unauthenticated requests against the Authentication Engine. Audit OAM-protected applications for signs of unauthorized data access and rotate credentials, sessions, and tokens if compromise is suspected.

Affected
Oracle Access Manager (Oracle Fusion Middleware, Authentication Engine component)12.2.1.4.0, 14.1.2.1.0
Estimated exposure
moderate≈ low thousands to ~10,000 internet-reachable OAM servers, plus a larger unknown number of internal enterprise deployments — Oracle Access Manager is licensed enterprise SSO middleware used mainly by mid-to-large organizations, and public internet scans typically surface only a few thousand exposed OAM endpoints, with most instances internal or VPN-protected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.