Executive brief
Oracle Access Manager is a critical component of Oracle Fusion Middleware that controls authentication and access to enterprise applications. This vulnerability allows unauthenticated attackers to remotely bypass SAML authentication and take over the Access Manager, potentially compromising all protected applications and sensitive data managed by the platform.
Technical details
This is an authentication bypass vulnerability in the Agent infrastructure component of Oracle Access Manager affecting versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability is exploitable via SAML protocol mechanisms without authentication and with no additional complexity (CVSS AV:N, AC:L, PR:N, UI:N). An unauthenticated attacker with network access can remotely exploit this flaw to achieve complete compromise of the Access Manager system, resulting in full confidentiality, integrity, and availability impact. A patch is likely available via Oracle's Critical Patch Update cycle.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-08-18: disclosed