Executive brief
Oracle Access Manager, a central component for managing user authentication and single sign-on across enterprise applications, contains a critical security flaw. An unauthorized person can exploit this over the network to gain full control of the system. This could lead to a total compromise of user identity data and unauthorized access to all applications protected by the manager.
Technical details
A critical vulnerability exists in the Authentication Engine component of Oracle Access Manager (part of Oracle Fusion Middleware). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows for a complete takeover of the Oracle Access Manager instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. While specific CWE details are not provided in the advisory, the CVSS vector indicates a low-complexity, remote attack requiring no user interaction or privileges.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-60328 by Oracle.