External risk intelligence

Oracle Access Manager Authentication Engine Vulnerability Allows Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-60333

Oracle Access Manager is an identity management and authentication solution designed to be public-facing or internet-adjacent to manage user access, authentication requests, and web single sign-on services, making it a common internet-exposed edge service in enterprise deployments.

Authentication Bypass

Oracle Access Manager

12.2.1.4.014.1.2.1.0

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in Oracle Access Manager, a component of Oracle Fusion Middleware. This issue is easily exploitable by an attacker with limited privileges who can access the system over the network via HTTP. Successful exploitation could lead to a complete takeover of Oracle Access Manager and potentially impact other connected products due to the nature of this authentication system.

  • Low-privilege access can compromise a key security system.
  • It manages user access, making its compromise a significant risk.
  • Confirm relevance and assess potential exposure to connected systems.

Attack Path

How an attacker could exploit the issue

An attacker with network access and low privileges could target Oracle Access Manager through HTTP. The vulnerability lies within the Authentication Engine, allowing for a successful attack that could lead to a complete takeover of the Oracle Access Manager, and potentially impact other connected products.

  • Network access and low privileges required.
  • Vulnerability in the Authentication Engine.
  • Risk of Oracle Access Manager takeover.

Live Threat

Current exploitation, exposure, and threat context

A low-privileged attacker with network access could compromise the Oracle Access Manager, potentially impacting other connected products. This could lead to a full takeover of the Oracle Access Manager system when supported.

  • Oracle Access Manager and associated products.
  • Network access via HTTP.
  • Takeover of Oracle Access Manager.

Operational Fix

Recommended remediation, mitigation, and detection steps

Security teams and platform owners are likely responsible for addressing this vulnerability in Oracle Access Manager. The immediate first step is to identify all instances of the affected product, confirm their network exposure, and assess their criticality to business operations. This information will help prioritize remediation efforts and engage the appropriate stakeholders, including potential vendor coordination if necessary.

  • Identify and confirm affected Oracle Access Manager instances.
  • Verify network exposure and business criticality.
  • Engage accountable owners for remediation planning.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Access Manager?

Oracle Access Manager is a core component of Oracle Fusion Middleware used to handle identity management, user authentication, and single sign-on services. Because it validates user credentials and manages access to protected applications, organizations typically deploy it as a central security gateway to control entry across their software ecosystem.

What does this CVE-2026-60333 vulnerability mean?

This vulnerability is a flaw within the Authentication Engine of Oracle Access Manager. It allows an attacker who already has low-level credentials to bypass security controls and potentially take full control of the system. Because this engine handles sensitive identity data, the compromise extends to the entire security layer the product protects, including other integrated systems.

How can an attacker trigger this vulnerability?

An attacker needs network access to reach the Oracle Access Manager via HTTP to attempt an exploit. The flaw requires the attacker to have at least low-privileged access to the system to initiate the attack sequence. It cannot be triggered by an unauthenticated user, nor does it require direct physical access to the server hardware.

Is my Oracle Access Manager deployment at risk?

According to Halo Surface Signal, Oracle Access Manager is often configured as an internet-facing or internet-adjacent service to facilitate single sign-on across enterprise environments. If your instance is reachable over the network, especially from the internet, it is a priority for review as it serves as a critical entry point for user authentication.

What should I do to address CVE-2026-60333?

Begin by creating a comprehensive inventory of all Oracle Access Manager instances within your environment to identify which systems are running versions 12.2.1.4.0 or 14.1.2.1.0. Determine which of these are reachable via the network and prioritize those with the highest business impact. Coordinate with your security and platform teams to prepare for official vendor patches provided by Oracle.

References