Junglewise Threat Intelligence

CVE-2026-60146: Oracle Access Manager data manipulation in Authentication Engine

CVE-2026-60146 · Severity: medium · CVSS 6.1 · Published 2026-07-21

Technologies: Oracle Access Manager. Vendors: Oracle.

Executive brief

Oracle Access Manager, a tool used to manage user identities and secure access to corporate applications, contains a security vulnerability in its authentication engine. An attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive data within the system. This could potentially lead to unauthorized access to other connected business applications.

Technical details

A vulnerability exists in the Authentication Engine component of Oracle Access Manager (versions 12.2.1.4.0 and 14.1.2.1.0). The flaw is easily exploitable by an unauthenticated attacker via the network using HTTP. Exploitation requires user interaction (UI:R) and results in a scope change (S:C), meaning the impact can extend beyond the Access Manager itself to other products in the Fusion Middleware stack. Attackers can achieve unauthorized read, update, insert, or delete access to a subset of data. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: advisory: Oracle published the security alert as part of the July 2026 CPU.
  • 2026-07-21: disclosed

References

Related threats