Executive brief
Oracle Access Manager, a tool used to manage user identities and control access to corporate applications, contains a critical security vulnerability in its authentication engine. An unauthorized attacker can exploit this over the network to gain full access to sensitive data or modify critical information without needing a username or password. This could lead to a total compromise of the identity management system, allowing attackers to create, delete, or steal sensitive corporate data.
Technical details
A vulnerability exists in the Authentication Engine component of Oracle Access Manager (part of Oracle Fusion Middleware). The flaw is categorized as easily exploitable, allowing an unauthenticated attacker with network access via HTTP to bypass or compromise the authentication process. Successful exploitation grants the attacker the ability to perform unauthorized creation, deletion, or modification of all data accessible to Oracle Access Manager, as well as providing complete read access to that data. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0. While the specific CWE is not detailed in the advisory, the impact focuses on Confidentiality and Integrity (CVSS 9.1).
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle via the July 2026 Critical Patch Update.
- 2026-07-21: advisory: NVD published the CVE record.