ZeroHour

CVE-2026-73944

moderate

Unauthenticated Data Access Flaw in Oracle Access Manager Authentication Engine

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-73944 is a critical (CVSS 9.1) vulnerability in the Authentication Engine component of Oracle Access Manager (OAM), part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction. A successful attack lets the attacker compromise Oracle Access Manager, gaining unauthorized creation, deletion, or modification of critical OAM data as well as unauthorized read access to critical data or all OAM-accessible data — though availability is not impacted (C:H/I:H/A:N). Because OAM typically fronts single sign-on for enterprise web applications, a compromise can cascade into access to the applications and identities it protects. There is no known public PoC, and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog as of this analysis.

What to do: Apply the Oracle Critical Patch Update that addresses this flaw to OAM 12.2.1.4.0 and 14.1.2.1.0 immediately, since the exploit is unauthenticated and trivially reachable over HTTP. Restrict network access to OAM endpoints (admin and SSO services) so only trusted networks and proxies can reach them. Review OAM audit and access logs for unauthenticated requests and unauthorized modifications to OAM configuration or user/session data, and rotate credentials, tokens, and session secrets if compromise is suspected.

Affected
Oracle Access Manager (Oracle Fusion Middleware, component: Authentication Engine)12.2.1.4.0
Oracle Access Manager (Oracle Fusion Middleware, component: Authentication Engine)14.1.2.1.0
Estimated exposure
moderateLikely a few thousand internet-exposed OAM deployments, fronting an estimated hundreds of thousands to millions of downstream SSO users — OAM is enterprise SSO middleware deployed mainly by mid-size and large organizations; public internet scans have historically shown on the order of low-thousands of exposed OAM endpoints, with many more on internal networks — this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Access Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.