ZeroHour

CVE-2026-83002

large

Authentication Engine Flaw in Oracle Access Manager Enables Full Takeover

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83002 is a high-severity vulnerability (CVSS 3.1: 8.5) in the Authentication Engine component of Oracle Access Manager, affecting versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Fusion Middleware. A remote attacker who already holds low-privilege credentials and has HTTP network access to the OAM server can trigger the flaw, although Oracle rates exploitation as difficult due to high attack complexity. Successful exploitation results in a complete takeover of Oracle Access Manager, and because the vulnerability has a scope change, successful attacks may significantly impact additional products beyond OAM itself. Organizations running the affected versions as their web single sign-on and access management layer are exposed, particularly where low-privilege accounts are broadly available (for example, customer or partner self-service portals). No public proof of concept exists, the issue is not on the CISA KEV list, and no in-the-wild exploitation is currently known.

What to do: Apply Oracle's Critical Patch Update fixes for Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0 as soon as they are available for your release line. Because exploitation requires only a low-privilege authenticated account, audit and constrain low-privilege user accounts, enforce MFA where possible, and restrict management and administrative endpoints from untrusted networks. Review authentication and session logs on OAM for anomalous behavior, and inventory downstream applications that trust OAM-issued assertions given the scope-change impact.

Affected
Oracle Access Manager (Oracle Fusion Middleware)
Estimated exposure
largelow tens of thousands of internet-reachable OAM servers (estimate), plus a larger unknown number of internal-only enterprise deployments — Oracle Access Manager is a widely deployed enterprise web SSO whose login endpoints are commonly fingerprinted by public internet scan engines in the low tens of thousands globally; each deployment typically serves large user populations.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.