Executive brief
Oracle Access Manager is an identity and access control system used to authenticate users and control access to enterprise applications. A vulnerability in its authentication engine allows a low-privileged attacker with network access to completely take over the system, potentially compromising confidentiality, integrity, and availability of protected applications and data. The attack requires difficult exploitation conditions but can impact other connected systems beyond Access Manager itself.
Technical details
This vulnerability exists in the Authentication Engine component of Oracle Access Manager (versions 12.2.1.4.0 and 14.1.2.1.0) and is classified as difficult to exploit. The vulnerability is remotely exploitable over HTTP by an attacker with low-level privileges. Successful exploitation results in complete takeover of the Oracle Access Manager system with changes to confidentiality, integrity, and availability (scope change per CVSS vector). While the root cause is not explicitly detailed in available sources, the authentication engine vulnerability combined with scope change indicates potential privilege escalation or authentication bypass capabilities. No active exploitation in the wild has been reported at the time of disclosure.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed