Junglewise Threat Intelligence

CVE-2026-70905: Oracle Access Manager SAML authentication bypass in Agent infrastructure

CVE-2026-70905 · Severity: critical · CVSS 9.8 · Published 2026-08-18

Technologies: Oracle Access Manager. Vendors: Oracle.

Executive brief

Oracle Access Manager is a critical component of Oracle Fusion Middleware that controls authentication and access to enterprise applications. This vulnerability allows unauthenticated attackers to remotely bypass SAML authentication and take over the Access Manager, potentially compromising all protected applications and sensitive data managed by the platform.

Technical details

This is an authentication bypass vulnerability in the Agent infrastructure component of Oracle Access Manager affecting versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability is exploitable via SAML protocol mechanisms without authentication and with no additional complexity (CVSS AV:N, AC:L, PR:N, UI:N). An unauthenticated attacker with network access can remotely exploit this flaw to achieve complete compromise of the Access Manager system, resulting in full confidentiality, integrity, and availability impact. A patch is likely available via Oracle's Critical Patch Update cycle.

Affected products

  • Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-08-18: disclosed

References

Related threats