ZeroHour

CVE-2026-73946

moderate

High-Privilege Remote Takeover Flaw in Oracle Access Manager Authentication Engine

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

Oracle Access Manager (OAM), the web single sign-on component of Oracle Fusion Middleware, contains a critical (CVSS 9.1) flaw in its Authentication Engine that allows a high-privileged attacker with network access via HTTP to fully take over the OAM installation. The vulnerability is rated easily exploitable, requires no user interaction, and carries a scope change, meaning successful attacks can significantly impact additional products beyond Oracle Access Manager itself. Successful exploitation compromises the confidentiality, integrity, and availability of OAM, which typically fronts authentication for an organization's web applications, so the blast radius can extend well past the SSO tier. Affected deployments are Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0. No public proof of concept is known, the CVE is not on CISA's Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update addressing CVE-2026-73946 to all OAM 12.2.1.4.0 and 14.1.2.1.0 installations as a priority. Because exploitation requires high privileges, tighten and audit administrative OAM accounts, enable strong authentication/MFA for them, and restrict HTTP access to OAM administration and console endpoints to trusted networks only. Review OAM authentication and admin logs for anomalous activity by privileged accounts, and assess downstream applications for signs of session or credential abuse given the scope-change impact.

Affected
Oracle Access Manager (Oracle Fusion Middleware, Authentication Engine component)12.2.1.4.0
Oracle Access Manager (Oracle Fusion Middleware, Authentication Engine component)14.1.2.1.0
Estimated exposure
moderatelow four figures (a few thousand) of internet-reachable OAM deployments, plus a larger unmeasured population of internal-only instances — OAM is enterprise IAM software deployed mainly at large organizations, and public internet scans (e.g., Shodan/Censys fingerprinting of OAM SSO login endpoints) typically show thousands of exposed instances; this is an order-of-magnitude…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.