Junglewise Threat Intelligence

CVE-2026-73941: Oracle Access Manager authentication bypass in Oracle Fusion Middleware

CVE-2026-73941 · Severity: high · CVSS 8.6 · Published 2026-09-15

Executive brief

Oracle Access Manager is a centralized authentication and authorization system used by enterprises to control access to applications and data. An unauthenticated attacker can exploit this vulnerability via the network to gain unauthorized access to sensitive data stored within Oracle Access Manager and potentially other connected systems. The flaw allows attackers to bypass authentication controls without requiring credentials or user interaction, posing a critical risk to customer data confidentiality.

Technical details

This is an authentication bypass vulnerability in the Authentication Engine component of Oracle Access Manager, affecting versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability is easily exploitable over the network via HTTP without requiring authentication or user interaction (network-accessible, no auth required). An unauthenticated attacker can achieve unauthorized access to critical data managed by Oracle Access Manager and potentially data from other integrated systems due to the scope change. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H) indicates a high-impact confidentiality breach with changed scope affecting other components.

Affected products

  • Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-09-15: disclosed

References

Related threats