Junglewise Threat Intelligence

CVE-2026-71133: Oracle Access Manager authentication bypass in HTTP

CVE-2026-71133 · Severity: critical · CVSS 10 · Published 2026-09-15

Executive brief

Oracle Access Manager is a critical authentication and authorization system used by enterprises to control access to applications and protect sensitive data. An unauthenticated attacker can exploit this vulnerability over the network without requiring any credentials or user interaction, leading to complete takeover of the system and potential compromise of all protected applications and customer data.

Technical details

This is a critical authentication bypass vulnerability in the Oracle Access Manager Authentication Engine. The vulnerability is easily exploitable via HTTP, allowing unauthenticated network attackers to achieve complete system compromise without authentication, credentials, or user interaction required. Successful exploitation results in full takeover of Oracle Access Manager with high impact to confidentiality, integrity, and availability. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0; patch availability and specific technical details are not provided in the advisory summary.

Affected products

  • Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0

Timeline

  • 2026-09-15: disclosed

References

Related threats