CVE-2026-73947
moderateUnauthenticated Takeover Flaw in Oracle Access Manager 12.2.1.4 and 14.1.2
A critical vulnerability (CVSS 9.8) in the Authentication Engine component of Oracle Access Manager (OAM), part of Oracle Fusion Middleware, allows an unauthenticated remote attacker with HTTP access to the server to completely take over the OAM installation. The flaw requires no privileges, no user interaction, and low attack complexity, so any internet-reachable OAM deployment is directly at risk; successful exploitation impacts confidentiality, integrity, and availability of the access management platform and, by extension, every application relying on it for single sign-on. Affected versions are OAM 12.2.1.4.0 and 14.2.0.0. Because OAM typically fronts enterprise authentication, a takeover can enable session theft and unauthorized access to downstream applications. As of this writing there is no known public proof of concept, the CVE is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported, though prior OAM flaws of this class have been targeted after disclosure.
What to do: Apply the Oracle Critical Patch Update that remediates this CVE to all OAM 12.2.1.4.0 and 14.2.0.0 installations as an emergency change. Until patched, restrict HTTP(S) access to OAM authentication and admin endpoints via firewall/VPN so only trusted networks can reach them, and enable WAF rules or virtual patching if the CPU guidance provides request signatures. Review OAM logs and configuration for unauthenticated anomalous requests, unexpected administrative sessions, or modified authentication policies that could indicate a compromise.
| Oracle Access Manager (Oracle Fusion Middleware, Authentication Engine component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.