Junglewise Threat Intelligence

CVE-2026-73940: Oracle Access Manager authentication engine remote code execution

CVE-2026-73940 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Executive brief

Oracle Access Manager is a critical authentication and authorization system used by enterprises to control access to applications and data. This vulnerability allows an unauthenticated attacker to completely take over the system remotely without any user interaction, compromising all protected applications and user data managed through the platform.

Technical details

This is a critical remote code execution vulnerability in the Oracle Access Manager authentication engine affecting versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability is easily exploitable by an unauthenticated attacker with network access via T3 or IIOP protocols, requiring no authentication or user interaction. Successful exploitation allows complete compromise of the Oracle Access Manager system, resulting in full confidentiality, integrity, and availability impacts. Oracle has published a security update addressing this issue.

Affected products

  • Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-09-15: disclosed

References

Related threats