Executive brief
A vulnerability exists in Oracle Access Manager, a tool used by organizations to manage user identities and control access to web applications. An attacker with basic user credentials can exploit this flaw over the network to take full control of the identity management system. This could lead to unauthorized access to sensitive corporate data, service disruptions, and the ability to manipulate user accounts across the enterprise.
Technical details
A vulnerability in the Authentication Engine component of Oracle Access Manager (part of Oracle Fusion Middleware) allows for a complete system takeover. The flaw is categorized as easily exploitable and requires only low-privileged user authentication to execute. The attack vector is remote via HTTP, and successful exploitation grants the attacker full control over Confidentiality, Integrity, and Availability (CIA triad) of the affected instance. Affected version is 14.1.2.1.0; users should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation guidance.
Affected products
- Oracle Access Manager 14.1.2.1.0
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-47037
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released