ZeroHour

CVE-2026-73962

moderate

Authenticated Access Bypass in Oracle Access Manager Enables Full Compromise

CVSS 3.1
9.6 critical
EPSS
Published
()
Modified
AI analysis

Oracle Access Manager (OAM), the SSO/authentication tier of Oracle Fusion Middleware, contains a critical flaw (CVSS 3.1 base 9.6) in its Authentication Engine affecting versions 12.2.1.4.0 and 14.1.2.1.0. A low-privileged attacker who already holds any valid account can exploit it over HTTPS with no user interaction, needing only network access and a low-complexity attack. Successful exploitation allows unauthorized creation, deletion, or modification of critical OAM data and complete read access to all data OAM can reach; because the scope changes, attacks can also significantly impact additional products that trust OAM for authentication. Any organization running the affected OAM versions as its web single sign-on layer is exposed, particularly where OAM endpoints are internet-facing. No public proof-of-concept is known, the flaw is not on CISA's KEV list, and no in-the-wild exploitation has been reported, though OAM flaws have historically attracted attackers after disclosure.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-73962 to OAM 12.2.1.4.0 and 14.1.2.1.0 (typically the April 2026 or later CPU bundle patch for each affected release). Restrict OAM administration and server endpoints to trusted networks or VPNs, and enforce MFA for accounts that can authenticate to OAM to blunt the low-privileged-attacker prerequisite. Review authentication policies, user stores, and audit logs on OAM instances for unauthorized changes or anomalous authenticated sessions.

Affected
Oracle Access Manager (Oracle Fusion Middleware, Authentication Engine component)12.2.1.4.0
Oracle Access Manager (Oracle Fusion Middleware, Authentication Engine component)14.1.2.1.0
Estimated exposure
moderate≈5,000–15,000 internet-exposed OAM deployments, with downstream user populations potentially far larger — OAM is enterprise on-premises software deployed by thousands of large organizations, and public internet scans (Shodan/Censys fingerprints of OAM login/server endpoints) have historically shown OAM instances in the low-thousands to ~15k…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Access Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.