Junglewise Threat Intelligence

CVE-2026-60333: Oracle Access Manager takeover via Authentication Engine

CVE-2026-60333 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Technologies: Oracle Access Manager. Vendors: Oracle.

Executive brief

Oracle Access Manager is a security tool used to manage user identities and control access to corporate applications. A critical vulnerability in its authentication engine allows a user with low-level access to take full control of the system. Because this tool manages access for other software, a successful attack could compromise multiple connected business systems and sensitive data.

Technical details

A vulnerability exists in the Authentication Engine component of Oracle Access Manager (part of Oracle Fusion Middleware). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. The vulnerability is characterized by a 'scope change' (CVSS S:C), meaning a successful exploit allows the attacker to move beyond the Access Manager and impact other integrated products. This can result in a complete compromise of confidentiality, integrity, and availability (takeover) of the affected environment. Affected versions include 12.2.1.4.0 and 14.1.2.1.0.

Affected products

  • Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60333

References

Related threats