ZeroHour

CVE-2026-73950

moderate

Unauthenticated Takeover Flaw in Oracle Access Manager Authentication Engine

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-73950 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager (OAM), part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. A successful attack allows complete takeover of Oracle Access Manager, with high impact on confidentiality, integrity, and availability (CVSS 9.8). Because OAM sits in the authentication path for single sign-on, compromise can cascade into the applications and identity flows it fronts. No public proof of concept is known and the flaw is not on the CISA KEV list, so exploitation status is currently none known.

What to do: Apply the Oracle Critical Patch Update that fixes CVE-2026-73950 to all OAM instances on 12.2.1.4.0 or 14.1.2.1.0, prioritizing any OAM servers reachable from the internet. Until patched, restrict HTTP access to OAM endpoints (especially admin and authentication URLs) via firewall/WAF rules to trusted sources. Review OAM and reverse-proxy logs for unauthenticated anomalous requests or unexpected configuration changes that could indicate compromise.

Affected
Oracle Access Manager (Oracle Fusion Middleware, Authentication Engine component)12.2.1.4.0, 14.1.2.1.0
Estimated exposure
moderatelow tens of thousands of internet-exposed OAM servers, plus internal enterprise deployments (estimate) — OAM is enterprise-only identity/access management software deployed on-premises and commonly internet-facing for SSO; public internet scans typically surface OAM authentication endpoints in the thousands-to-tens-of-thousands range, while…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.