Executive brief
Oracle Access Manager is the authentication and authorization component of Oracle Fusion Middleware used to control access to enterprise applications. This vulnerability allows a high-privilege attacker with network access to fully compromise the authentication system, potentially gaining control over user authentication decisions and impacting all dependent applications. A successful attack could enable account takeover, unauthorized access to protected resources, and data breach across multiple systems.
Technical details
This vulnerability affects the Authentication Engine component in Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0, exploitable via HTTP by high-privileged network-connected attackers without requiring user interaction. The vulnerability is easily exploitable and allows full compromise of the Access Manager with scope change, meaning successful exploitation can impact the confidentiality, integrity, and availability of not only Access Manager itself but also dependent systems and applications that rely on it for authentication and authorization decisions. Patch availability and detailed technical remediation should be obtained directly from Oracle security advisories.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed