Executive brief
Oracle Access Manager, a tool used to manage user identity and secure access to corporate applications, contains a high-severity vulnerability in its authentication engine. An unauthorized attacker could exploit this flaw over the network to gain full control of the system. A successful attack would allow the intruder to compromise sensitive data, disrupt operations, and potentially take over the entire identity management infrastructure.
Technical details
A vulnerability exists in the Authentication Engine component of Oracle Access Manager (part of Oracle Fusion Middleware). The flaw allows an unauthenticated attacker with network access via HTTP to compromise the application, potentially leading to a complete takeover. While the attack vector is network-based and requires no privileges or user interaction, Oracle classifies the exploit complexity as 'High,' suggesting specific environmental conditions or timing may be required for success. The vulnerability impacts confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory