Junglewise Threat Intelligence

CVE-2026-73945: Oracle Access Manager authentication bypass in Oracle Fusion Middleware

CVE-2026-73945 · Severity: critical · CVSS 9.9 · Published 2026-09-15

Executive brief

Oracle Access Manager is a critical authentication and authorization system used to control access to corporate applications and data across enterprise environments. A network-accessible vulnerability in its authentication engine allows low-privileged attackers to completely compromise the system, potentially gaining unauthorized access to all protected applications and sensitive data. This impact extends beyond Access Manager itself to the entire application ecosystem it protects.

Technical details

This vulnerability exists in the Authentication Engine component of Oracle Access Manager (versions 12.2.1.4.0 and 14.1.2.1.0) and is easily exploitable via HTTP by an attacker with low privilege access and network connectivity. The vulnerability allows an authenticated attacker to bypass authentication controls or escalate privileges, resulting in complete compromise of the Access Manager system. The scope impact indicates that successful exploitation significantly affects the confidentiality, integrity, and availability of not only Access Manager but also downstream systems that depend on it for authentication. Patches are expected to be available through Oracle's standard security update process.

Affected products

  • Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-09-15: disclosed

References

Related threats