Executive brief
Oracle Access Manager is a security tool used to manage user identities and control access to corporate applications. A vulnerability in its authentication engine allows an attacker on the same local network to take full control of the system. This could lead to unauthorized access to sensitive business data, service disruptions, and the compromise of user credentials across the organization.
Technical details
A vulnerability exists in the Authentication Engine component of Oracle Access Manager (part of Oracle Fusion Middleware). The flaw is categorized as easily exploitable but requires the attacker to be on the same physical or logical network segment (Adjacent vector) as the target hardware. An attacker with low-level privileges can exploit this to achieve a complete takeover of the Oracle Access Manager instance, impacting confidentiality, integrity, and availability. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory