Junglewise Threat Intelligence

CVE-2026-61065: Oracle Access Manager compromise in Authentication Engine

CVE-2026-61065 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle Access Manager. Vendors: Oracle.

Executive brief

A critical vulnerability has been identified in Oracle Access Manager, a central component of Oracle Fusion Middleware used for managing user authentication and single sign-on across enterprise applications. An unauthenticated attacker can exploit this flaw over the network to gain full control of the Access Manager system. This could lead to a complete compromise of corporate identity services, unauthorized access to sensitive data, and disruption of business operations.

Technical details

This vulnerability exists within the Authentication Engine component of Oracle Access Manager (OAM). It is classified as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the OAM instance. Successful exploitation results in a complete takeover of the product, impacting confidentiality, integrity, and availability (CVSS 9.8). The attack does not require user interaction or elevated privileges. Organizations using affected versions 12.2.1.4.0 and 14.1.2.1.0 should apply the relevant patches from the Oracle Critical Patch Update (CPU) immediately.

Affected products

  • Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication

References

Related threats