CVE-2026-73958
moderateUnauthenticated HTTP Takeover Flaw in Oracle Access Manager Authentication Engine
Oracle Access Manager (OAM), the web single-sign-on component of Oracle Fusion Middleware, contains a vulnerability in its Authentication Engine that lets an unauthenticated attacker with network access via HTTP take over the OAM instance. The flaw requires no privileges or user interaction, but the attack complexity is high (AC:H), meaning successful exploitation likely demands precise or repeated crafted requests. A successful attack results in full compromise of Oracle Access Manager with high impact to confidentiality, integrity, and availability — and since OAM typically fronts authentication for many downstream applications, its takeover can cascade into broader session and access abuse. Affected versions are 12.2.1.4.0 and 14.1.2.0.0, which are the standard long-lived support releases used across many enterprise and government deployments. No public proof-of-concept is known, the issue is not on the CISA KEV list, and there is no evidence of in-the-wild exploitation at this time.
What to do: Apply the Oracle Critical Patch Update (CPU) that remediates this CVE to all OAM 12.2.1.4.0 and 14.1.2.0.0 deployments — Oracle ships OAM fixes only through its patch pipeline, so confirm you are on the latest available bundle patch for each release train. Prioritize internet-facing OAM authentication endpoints for patching, restrict direct HTTP exposure to admin consoles where possible, and review logs for anomalous unauthenticated HTTP traffic to authentication endpoints or unexpected administrative/session changes.
| Oracle Access Manager (Oracle Fusion Middleware, component: Authentication Engine) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.