Executive brief
Oracle Access Manager, a tool used to manage user identities and control access to corporate applications, contains a vulnerability in its authentication engine. An unauthenticated attacker can exploit this over the network to gain unauthorized access to sensitive data. This could lead to a significant breach of confidential information across multiple connected systems and services.
Technical details
A vulnerability exists in the Authentication Engine component of Oracle Access Manager (versions 12.2.1.4.0 and 14.1.2.1.0). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation results in a scope change (S:C), meaning the impact can extend beyond Oracle Access Manager to other integrated products. The primary impact is a high loss of confidentiality (C:H), potentially granting the attacker complete access to all data accessible by the manager. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD record published