ZeroHour

CVE-2026-73945

moderate

Authenticated HTTP Takeover Flaw in Oracle Access Manager Authentication Engine (CVSS 9.9)

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-73945 is a critical flaw in the Authentication Engine component of Oracle Access Manager (OAM), part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. A low-privileged attacker with network access via HTTP can exploit it easily (no user interaction required), and because the vulnerability's scope changes, successful attacks can significantly impact products beyond OAM itself. A successful exploit results in full takeover of Oracle Access Manager with high impact to confidentiality, integrity, and availability — alarming for an identity/SSO product that brokers access to downstream applications. Any organization exposing an affected OAM deployment (commonly enterprises, governments, and financial institutions using it for web SSO) is affected. No public proof-of-concept exists and the flaw is not on the CISA KEV catalog, so no exploitation in the wild is currently known.

What to do: Apply the Oracle Critical Patch Update that remediates this CVE to both OAM 12.2.1.4.0 and 14.1.2.1.0 deployments as soon as it is available. In the interim, restrict network access to OAM HTTP endpoints (especially from untrusted networks), enforce strict authentication and least-privilege on OAM user accounts, and place WAF rules or reverse-proxy controls in front of OAM consoles. Review OAM audit logs for anomalous activity by low-privileged accounts, unexpected administrative changes, and any newly created agents or sessions, since compromise of OAM can cascade to all federated applications.

Affected
Oracle Access Manager (Oracle Fusion Middleware)12.2.1.4.0
Oracle Access Manager (Oracle Fusion Middleware)14.1.2.1.0
Estimated exposure
moderate≈ several thousand (order of 1k–10k) internet-exposed OAM deployments — OAM is enterprise-only software deployed by large organizations, and public internet scans (e.g., Shodan/Censys queries for OAM login lander pages) have historically shown a few thousand to low tens of thousands of internet-facing…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.