ZeroHour

CVE-2026-73947

moderate

Unauthenticated Takeover Flaw in Oracle Access Manager 12.2.1.4 and 14.1.2

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

A critical vulnerability (CVSS 9.8) in the Authentication Engine component of Oracle Access Manager (OAM), part of Oracle Fusion Middleware, allows an unauthenticated remote attacker with HTTP access to the server to completely take over the OAM installation. The flaw requires no privileges, no user interaction, and low attack complexity, so any internet-reachable OAM deployment is directly at risk; successful exploitation impacts confidentiality, integrity, and availability of the access management platform and, by extension, every application relying on it for single sign-on. Affected versions are OAM 12.2.1.4.0 and 14.2.0.0. Because OAM typically fronts enterprise authentication, a takeover can enable session theft and unauthorized access to downstream applications. As of this writing there is no known public proof of concept, the CVE is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported, though prior OAM flaws of this class have been targeted after disclosure.

What to do: Apply the Oracle Critical Patch Update that remediates this CVE to all OAM 12.2.1.4.0 and 14.2.0.0 installations as an emergency change. Until patched, restrict HTTP(S) access to OAM authentication and admin endpoints via firewall/VPN so only trusted networks can reach them, and enable WAF rules or virtual patching if the CPU guidance provides request signatures. Review OAM logs and configuration for unauthenticated anomalous requests, unexpected administrative sessions, or modified authentication policies that could indicate a compromise.

Affected
Oracle Access Manager (Oracle Fusion Middleware, Authentication Engine component)
Estimated exposure
moderate≈10,000+ internet-exposed OAM deployments (likely low tens of thousands, plus a larger unmeasured base of internal-only instances) — OAM is an enterprise SSO product commonly deployed at network perimeters, and public internet scans (Shodan/Censys) have historically shown tens of thousands of reachable OAM login and admin endpoints.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.