ZeroHour

CVE-2026-73958

moderate

Unauthenticated HTTP Takeover Flaw in Oracle Access Manager Authentication Engine

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

Oracle Access Manager (OAM), the web single-sign-on component of Oracle Fusion Middleware, contains a vulnerability in its Authentication Engine that lets an unauthenticated attacker with network access via HTTP take over the OAM instance. The flaw requires no privileges or user interaction, but the attack complexity is high (AC:H), meaning successful exploitation likely demands precise or repeated crafted requests. A successful attack results in full compromise of Oracle Access Manager with high impact to confidentiality, integrity, and availability — and since OAM typically fronts authentication for many downstream applications, its takeover can cascade into broader session and access abuse. Affected versions are 12.2.1.4.0 and 14.1.2.0.0, which are the standard long-lived support releases used across many enterprise and government deployments. No public proof-of-concept is known, the issue is not on the CISA KEV list, and there is no evidence of in-the-wild exploitation at this time.

What to do: Apply the Oracle Critical Patch Update (CPU) that remediates this CVE to all OAM 12.2.1.4.0 and 14.1.2.0.0 deployments — Oracle ships OAM fixes only through its patch pipeline, so confirm you are on the latest available bundle patch for each release train. Prioritize internet-facing OAM authentication endpoints for patching, restrict direct HTTP exposure to admin consoles where possible, and review logs for anomalous unauthenticated HTTP traffic to authentication endpoints or unexpected administrative/session changes.

Affected
Oracle Access Manager (Oracle Fusion Middleware, component: Authentication Engine)
Estimated exposure
moderatethousands to low tens of thousands of OAM deployments, many with internet-facing SSO endpoints (order of magnitude ≈10,000) — OAM is per-organization enterprise middleware with no public install counts; public internet scans of OAM-identifiable login/SSO endpoints have historically shown low-thousands to tens-of-thousands of exposed instances, concentrated at…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.