Executive brief
Oracle Access Manager is a critical identity and access control system used to protect enterprise applications and data by managing user authentication and authorization. This vulnerability allows an attacker with low-level credentials and network access to bypass authentication controls via HTTP, leading to unauthorized access to sensitive data, modification of critical information, and potential service disruption across Oracle Fusion Middleware and connected systems.
Technical details
This is an authentication bypass vulnerability in the Oracle Access Manager Authentication Engine, exploitable with low-privilege network access via HTTP (no authentication required beyond network reachability, though advisory mentions "low privileged attacker"). The vulnerability has a CVSS 3.1 score of 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L), indicating network attack vector with low complexity and changed scope. Successful exploitation permits unauthorized creation, deletion, or modification of critical data; complete access to all Oracle Access Manager-accessible data; confidentiality, integrity, and availability impacts; and partial denial of service. Affected versions are 12.2.1.4.0 and 14.1.2.1.0. Patch availability was expected as of the September 2026 security advisory, though the external Oracle reference URL was inaccessible at time of analysis.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed: Public disclosure via Oracle security alert