CVE-2026-83002
largeAuthentication Engine Flaw in Oracle Access Manager Enables Full Takeover
CVE-2026-83002 is a high-severity vulnerability (CVSS 3.1: 8.5) in the Authentication Engine component of Oracle Access Manager, affecting versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Fusion Middleware. A remote attacker who already holds low-privilege credentials and has HTTP network access to the OAM server can trigger the flaw, although Oracle rates exploitation as difficult due to high attack complexity. Successful exploitation results in a complete takeover of Oracle Access Manager, and because the vulnerability has a scope change, successful attacks may significantly impact additional products beyond OAM itself. Organizations running the affected versions as their web single sign-on and access management layer are exposed, particularly where low-privilege accounts are broadly available (for example, customer or partner self-service portals). No public proof of concept exists, the issue is not on the CISA KEV list, and no in-the-wild exploitation is currently known.
What to do: Apply Oracle's Critical Patch Update fixes for Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0 as soon as they are available for your release line. Because exploitation requires only a low-privilege authenticated account, audit and constrain low-privilege user accounts, enforce MFA where possible, and restrict management and administrative endpoints from untrusted networks. Review authentication and session logs on OAM for anomalous behavior, and inventory downstream applications that trust OAM-issued assertions given the scope-change impact.
| Oracle Access Manager (Oracle Fusion Middleware) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.