Junglewise Threat Intelligence

CVE-2026-35313: Oracle Access Manager improper access control in Authentication Engine

CVE-2026-35313 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Oracle Access Manager. Vendors: Oracle.

Executive brief

Oracle Access Manager, a critical tool used to manage user identities and control access to corporate applications, contains a severe security flaw in its authentication engine. A user with very basic access to the network can exploit this weakness to take full control of the system. Because this tool manages access for many other business applications, a successful attack could allow an unauthorized person to compromise multiple connected systems and sensitive data across the organization.

Technical details

A vulnerability classified as Improper Access Control (CWE-284) exists in the Authentication Engine component of Oracle Access Manager. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Due to a scope change (Status: Changed in CVSS), a successful exploit allows the attacker to not only take over Oracle Access Manager but also significantly impact additional integrated products. This affects versions 12.2.1.4.0 and 14.1.2.1.0. Security patches are typically released via the Oracle Critical Patch Update (CPU) program.

Affected products

  • Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle June 2026 Security Alert published

References

Related threats