External risk intelligence

Oracle Access Manager Authentication Engine Vulnerability Allows Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60328

Oracle Access Manager is an identity management and access control solution. It is designed to be public-facing to manage authentication for users and services, often acting as a gateway for web applications and enterprise security, making it inherently likely to be exposed to the internet in common deployment patterns.

Authentication Bypass

Oracle Access Manager

12.2.1.4.014.1.2.1.0

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability in Oracle Access Manager, a component of Oracle Fusion Middleware. The issue, easily exploitable by an unauthenticated attacker over the network, could lead to a complete takeover of the Access Manager system, impacting confidentiality, integrity, and availability with severe consequences.

  • Unauthenticated attackers can take over Access Manager.
  • It protects access to other enterprise systems.
  • Confirm if our Oracle Access Manager is exposed.

Attack Path

How an attacker could exploit the issue

An attacker can target Oracle Access Manager by exploiting a vulnerability in its Authentication Engine. This vulnerability is accessible over the network via HTTP and does not require any prior authentication, meaning an attacker can attempt to exploit it directly. Successful exploitation could lead to a complete takeover of the Oracle Access Manager, compromising its security functions.

  • Attacker needs network access.
  • Vulnerable component is the Authentication Engine.
  • Risk is a full system takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access to compromise Oracle Access Manager, potentially leading to a complete takeover of the system. This could affect the confidentiality, integrity, and availability of the access management service and any resources it protects.

  • Oracle Access Manager system.
  • Network access via HTTP.
  • Complete system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Oracle Access Manager component within Oracle Fusion Middleware, particularly versions 12.2.1.4.0 and 14.1.2.1.0, is susceptible to a critical vulnerability. Unauthenticated attackers with network access can exploit this flaw via HTTP, potentially leading to a complete takeover of the Oracle Access Manager system. Initial actions should focus on identifying all instances of the affected technology, assessing their business criticality and network exposure, and pinpointing the accountable system owner to plan a risk-based remediation strategy.

  • Identify and confirm Oracle Access Manager instances.
  • Verify network exposure and business criticality.
  • Plan remediation with accountable system owner.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Access Manager?

Oracle Access Manager is a component of Oracle Fusion Middleware used for identity management and access control. It serves as a central gateway for authentication, managing how users and services gain entry to web applications and enterprise systems. Because it often guards critical resources, it is designed to be highly integrated into organizational security workflows.

What does CVE-2026-60328 mean for system security?

CVE-2026-60328 describes a critical vulnerability within the product's Authentication Engine. In technical terms, it allows an unauthenticated user to bypass standard security controls. Because the Authentication Engine is responsible for verifying identities, a flaw here can allow an attacker to gain full control over the entire system, compromising the confidentiality, integrity, and availability of all managed access paths.

How can an attacker trigger this vulnerability?

An attacker triggers this flaw by sending specifically crafted HTTP requests over the network to the Authentication Engine. Because the vulnerability does not require any prior authentication or special user privileges, the system will process these malicious requests automatically. It is important to note that the flaw is not triggered by normal, authorized user login activity, but rather by external requests intended to subvert the engine's processing logic.

Why is this CVE considered relevant to my environment?

Halo Surface Signal indicates that Oracle Access Manager is often deployed as a public-facing gateway to handle external traffic, making it a frequent target for network-based attacks. If your instances are reachable from the internet, the barrier for an attacker is significantly lower. Even internal instances should be reviewed, as any device with network access to the component can potentially initiate the exploit.

Do I need to take action if I run these versions?

Yes, you should begin by creating a comprehensive inventory of all Oracle Access Manager deployments to identify which servers are running versions 12.2.1.4.0 or 14.1.2.1.0. Once identified, prioritize these systems based on their network accessibility and the sensitivity of the applications they protect. Coordinate with your system owners to review the official Oracle security updates for the July 2026 release cycle to plan your patching strategy.

References