ZeroHour

CVE-2026-83001

large

Privileged Remote Takeover Flaw in Oracle Access Manager 12.2.1.4.0 / 14.1.2.1.0

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

A critical (CVSS 9.1) vulnerability exists in the Authentication Engine component of Oracle Access Manager (OAM), part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It is easily exploitable over the network via HTTP, but requires a highly privileged (already authenticated, admin-level) account, meaning it is a post-authentication takeover vector rather than an anonymous attack. Successful exploitation lets the attacker fully compromise Oracle Access Manager — with complete impact on confidentiality, integrity, and availability — and because the scope changes, downstream products and services that rely on OAM for single sign-on and authentication can also be significantly impacted. Any organization running the two affected OAM versions as its federated identity/SSO layer is exposed, particularly if administrative OAM endpoints are reachable over the network. There is no known public proof-of-concept and no evidence of in-the-wild exploitation at this time.

What to do: Apply the Oracle Critical Patch Update covering CVE-2026-83001 to OAM 12.2.1.4.0 and 14.1.2.1.0 as the top priority, since OAM is a tier-0 identity asset even for a privileged-only flaw. Restrict network access to the OAM administration console and administrative APIs (allow-list admin networks, enforce MFA for privileged accounts) to shrink the pool of would-be attackers. Review OAM and web server logs for anomalous activity by high-privileged accounts and verify that SSO-protected downstream applications have not been tampered with.

Affected
Oracle Access Manager (Oracle Fusion Middleware, component: Authentication Engine)12.2.1.4.0, 14.1.2.1.0
Estimated exposure
large≈tens of thousands of internet-reachable OAM deployments (roughly 10k-50k exposed hosts), plus a larger unknown base of internal enterprise instances — OAM is enterprise IAM middleware deployed by large organizations, and public internet scans (e.g., for /oam/ endpoints) historically show tens of thousands of exposed instances, though only the two listed versions are vulnerable.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.