Executive brief
Oracle Access Manager, a tool used to manage user logins and security permissions for corporate applications, contains a vulnerability in its authentication engine. An unauthorized person could use this flaw over the internet to gain access to sensitive corporate data. Because this system controls access to many other applications, a successful attack could allow an intruder to see information across multiple different business systems.
Technical details
A vulnerability exists in the Authentication Engine component of Oracle Access Manager (versions 12.2.1.4.0 and 14.1.2.1.0). This is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. The vulnerability is notable for a 'scope change' (S:C), meaning a successful exploit can impact security across other products integrated with the Access Manager. The primary impact is a total loss of confidentiality (C:H) for all data accessible to the manager. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory