CVE-2026-73946
moderateHigh-Privilege Remote Takeover Flaw in Oracle Access Manager Authentication Engine
Oracle Access Manager (OAM), the web single sign-on component of Oracle Fusion Middleware, contains a critical (CVSS 9.1) flaw in its Authentication Engine that allows a high-privileged attacker with network access via HTTP to fully take over the OAM installation. The vulnerability is rated easily exploitable, requires no user interaction, and carries a scope change, meaning successful attacks can significantly impact additional products beyond Oracle Access Manager itself. Successful exploitation compromises the confidentiality, integrity, and availability of OAM, which typically fronts authentication for an organization's web applications, so the blast radius can extend well past the SSO tier. Affected deployments are Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0. No public proof of concept is known, the CVE is not on CISA's Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update addressing CVE-2026-73946 to all OAM 12.2.1.4.0 and 14.1.2.1.0 installations as a priority. Because exploitation requires high privileges, tighten and audit administrative OAM accounts, enable strong authentication/MFA for them, and restrict HTTP access to OAM administration and console endpoints to trusted networks only. Review OAM authentication and admin logs for anomalous activity by privileged accounts, and assess downstream applications for signs of session or credential abuse given the scope-change impact.
| Oracle Access Manager (Oracle Fusion Middleware, Authentication Engine component) | 12.2.1.4.0 |
| Oracle Access Manager (Oracle Fusion Middleware, Authentication Engine component) | 14.1.2.1.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.