Junglewise Threat Intelligence

CVE-2026-83369: Oracle Access Manager denial of service in Access SDK

CVE-2026-83369 · Severity: low · CVSS 3.1 · Published 2026-09-15

Executive brief

Oracle Access Manager is a component of Oracle Fusion Middleware used to control and manage access to corporate applications and resources. A vulnerability in its Access SDK component allows authenticated users with network access to partially disrupt service availability, potentially affecting the ability of legitimate users to access protected applications.

Technical details

This is a denial-of-service vulnerability in the Access SDK component of Oracle Access Manager. It requires network access via HTTP and a low-privileged account to exploit, though the attack is difficult to execute (high complexity requirement). The vulnerability results in partial availability impact to the Access Manager service. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. Patches are expected to be available from Oracle's security updates.

Affected products

  • Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-09-15: disclosed

References

Related threats