Executive brief
Oracle Access Manager is a centralized authentication and authorization system used to protect enterprise applications and control user access across organizations. An unauthenticated attacker can exploit this vulnerability remotely via HTTP to completely compromise the system, potentially gaining unauthorized access to all protected applications and sensitive business data.
Technical details
This is a critical authentication bypass vulnerability in the Authentication Engine component of Oracle Access Manager. The vulnerability is easily exploitable and requires no authentication, no special privileges, and no user interaction—an attacker needs only network access to the HTTP interface to trigger the flaw. Successful exploitation results in complete system compromise including confidentiality, integrity, and availability impacts. The vulnerability affects Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0. Patch status and remediation details are not yet available from the referenced Oracle security advisories.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed