Junglewise Threat Intelligence

CVE-2026-73944: Oracle Access Manager authentication bypass in HTTP

CVE-2026-73944 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Executive brief

Oracle Access Manager is a security product used to protect access to enterprise applications and data. An unauthenticated attacker can exploit an easily exploitable vulnerability via HTTP to gain unauthorized access, create, modify, or delete critical data without authentication, compromising confidentiality and integrity of all data managed by the system.

Technical details

This vulnerability in the Authentication Engine component of Oracle Access Manager allows unauthenticated attackers with network access to compromise the system via HTTP. The vulnerability is easily exploitable with no authentication required, no user interaction needed, and no privilege escalation necessary. Successful attacks can result in unauthorized data creation, deletion, and modification, as well as complete unauthorized access to all Access Manager-accessible data. The vulnerability affects supported versions 12.2.1.4.0 and 14.1.2.1.0; patch availability should be confirmed with Oracle security advisories.

Affected products

  • Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-09-15: disclosed

References

Related threats