Executive brief
Oracle Access Manager is a critical identity and access management component used to control authentication and authorization across enterprise systems. A high-severity vulnerability in its Authentication Engine allows an attacker with administrative privileges and network access to completely compromise the system, potentially affecting dependent applications and exposing sensitive user data and business operations.
Technical details
This is an authentication bypass or privilege escalation vulnerability in the Authentication Engine component of Oracle Access Manager, affecting versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability is easily exploitable via HTTP by a high-privileged attacker with network access, requiring no user interaction. Successful exploitation allows complete system takeover with impacts on confidentiality, integrity, and availability, and the scope is marked as changed, meaning the attack impacts resources beyond the vulnerable component itself. No active exploitation in the wild has been reported as of the disclosure date.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed