CVE-2026-73944
moderateUnauthenticated Data Access Flaw in Oracle Access Manager Authentication Engine
CVE-2026-73944 is a critical (CVSS 9.1) vulnerability in the Authentication Engine component of Oracle Access Manager (OAM), part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction. A successful attack lets the attacker compromise Oracle Access Manager, gaining unauthorized creation, deletion, or modification of critical OAM data as well as unauthorized read access to critical data or all OAM-accessible data — though availability is not impacted (C:H/I:H/A:N). Because OAM typically fronts single sign-on for enterprise web applications, a compromise can cascade into access to the applications and identities it protects. There is no known public PoC, and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog as of this analysis.
What to do: Apply the Oracle Critical Patch Update that addresses this flaw to OAM 12.2.1.4.0 and 14.1.2.1.0 immediately, since the exploit is unauthenticated and trivially reachable over HTTP. Restrict network access to OAM endpoints (admin and SSO services) so only trusted networks and proxies can reach them. Review OAM audit and access logs for unauthenticated requests and unauthorized modifications to OAM configuration or user/session data, and rotate credentials, tokens, and session secrets if compromise is suspected.
| Oracle Access Manager (Oracle Fusion Middleware, component: Authentication Engine) | 12.2.1.4.0 |
| Oracle Access Manager (Oracle Fusion Middleware, component: Authentication Engine) | 14.1.2.1.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Access Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.