Junglewise Threat Intelligence

CVE-2026-73947: Oracle Access Manager remote code execution in Authentication Engine

CVE-2026-73947 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Executive brief

Oracle Access Manager is an enterprise authentication and identity management system used to control access to corporate applications and resources. This vulnerability allows an unauthenticated attacker to remotely compromise the system via network access, potentially gaining complete control over authentication policies, user credentials, and access to protected applications. A successful exploit could enable unauthorized access to all systems protected by the Access Manager, leading to data theft, fraud, or complete compromise of enterprise operations.

Technical details

This vulnerability exists in the Authentication Engine component of Oracle Access Manager and affects versions 12.2.1.4.0 and 14.1.2.0.0. The flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to achieve remote code execution without authentication or user interaction required. The attack vector is network-based with low attack complexity and no privilege escalation needed. Successful exploitation results in complete system compromise, affecting confidentiality, integrity, and availability of the Access Manager service. Patch availability and specific technical remediation details have not yet been disclosed.

Affected products

  • Oracle Access Manager 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed: Vulnerability published by Oracle

References

Related threats