Executive brief
A vulnerability exists in Oracle Access Manager, a tool used by organizations to manage user identities and control access to web applications. An unauthenticated attacker can exploit this flaw over the network to gain unauthorized access to sensitive data or modify existing records. This could lead to data breaches or the unauthorized alteration of user permissions and identity information.
Technical details
An improper authentication vulnerability (CWE-287) exists in the Authentication Engine component of Oracle Access Manager. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows the attacker to perform unauthorized read, update, insert, or delete operations on a subset of data managed by Oracle Access Manager. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory