Executive brief
Oracle Access Manager, a critical tool used to manage user identities and control access to corporate applications, contains a security flaw in its authentication engine. An attacker with access to the local network can exploit this vulnerability to take full control of the system. This could lead to a total loss of confidentiality, unauthorized data modification, and service outages across the organization's identity infrastructure.
Technical details
A vulnerability exists in the Authentication Engine component of Oracle Access Manager within Oracle Fusion Middleware. The flaw is categorized as easily exploitable and requires the attacker to have low-level privileges and access to the adjacent network (physical communication segment) where the hardware resides. Successful exploitation allows for a complete takeover of the Oracle Access Manager instance, impacting confidentiality, integrity, and availability. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory