Junglewise Threat Intelligence

CVE-2026-60358: Oracle Access Manager compromise in Authentication Engine

CVE-2026-60358 · Severity: critical · CVSS 10 · Published 2026-07-21

Technologies: Oracle Access Manager. Vendors: Oracle.

Executive brief

Oracle Access Manager, a critical tool used for managing user identities and controlling access to corporate applications, contains a severe security flaw. An unauthorized person can use this vulnerability over the internet to take complete control of the system without needing a password. Because this tool manages access for many other business systems, a successful attack could allow the intruder to compromise additional connected applications and data across the organization.

Technical details

A critical vulnerability exists in the Authentication Engine component of Oracle Access Manager (versions 12.2.1.4.0 and 14.1.2.1.0). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. The vulnerability is characterized by a 'scope change' (CVSS S:C), meaning that a successful compromise of the Authentication Engine can be leveraged to attack and impact other products integrated with the identity provider. This can result in a total loss of confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: disclosed: Initial publication of the vulnerability advisory.
  • 2026-07-21: advisory: Included in the Oracle Critical Patch Update for July 2026.

References

Related threats