Junglewise Threat Intelligence

CVE-2026-73926: Oracle Access Manager authentication engine privilege escalation

CVE-2026-73926 · Severity: high · CVSS 8.7 · Published 2026-09-15

Executive brief

Oracle Access Manager is the authentication and authorization component of Oracle Fusion Middleware, used to control who can access enterprise applications and data. A vulnerability in its authentication engine allows a high-privileged attacker with network access to modify or delete critical data and gain unauthorized access to sensitive information managed by the system, potentially compromising multiple connected applications.

Technical details

The vulnerability exists in the Authentication Engine component of Oracle Access Manager and is exploitable via HTTP with high privileges and no user interaction required. It allows remote attackers to achieve unauthorized creation, deletion, or modification of critical data and unauthorized access to sensitive data. The vulnerability has a scope change, meaning successful exploitation may impact additional Oracle products beyond Access Manager itself. The affected versions are 12.2.1.4.0 and 14.1.2.1.0. No patch information is currently available in the advisory.

Affected products

  • Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-09-15: disclosed

References

Related threats