Executive brief
Oracle Access Manager is a security tool used to manage user identities and control access to corporate applications. A critical vulnerability in its authentication engine allows a user with low-level access to take full control of the system. Because this tool manages access for other software, a successful attack could compromise multiple connected business systems and sensitive data.
Technical details
A vulnerability exists in the Authentication Engine component of Oracle Access Manager (part of Oracle Fusion Middleware). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. The vulnerability is characterized by a 'scope change' (CVSS S:C), meaning a successful exploit allows the attacker to move beyond the Access Manager and impact other integrated products. This can result in a complete compromise of confidentiality, integrity, and availability (takeover) of the affected environment. Affected versions include 12.2.1.4.0 and 14.1.2.1.0.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-60333