Junglewise Threat Intelligence

CVE-2026-73958: Oracle Access Manager authentication bypass in HTTP

CVE-2026-73958 · Severity: high · CVSS 8.1 · Published 2026-09-15

Executive brief

Oracle Access Manager is a critical authentication and access control system used to protect Oracle Fusion Middleware deployments and enterprise applications. An unauthenticated attacker with network access can exploit a difficult-to-exploit vulnerability in the authentication engine to fully compromise the system, leading to complete loss of confidentiality, integrity, and availability of the affected infrastructure.

Technical details

This vulnerability in Oracle Access Manager's Authentication Engine allows unauthenticated attackers to compromise the product via HTTP. The attack requires network access but no user interaction. Exploitation is rated as difficult, yet successful attacks result in complete system compromise (CVSS 8.1 with high impacts across confidentiality, integrity, and availability). The vulnerability affects supported versions 12.2.1.4.0 and 14.1.2.0.0. Patch status is indicated by the publication date of September 2026, and no current information confirms public exploit availability.

Affected products

  • Oracle Access Manager 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats