External risk intelligence

Oracle Access Manager Authentication Engine Vulnerability Leads to Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60355

Oracle Access Manager is an identity management and access gateway product designed to handle authentication requests. By its architectural nature, this component is deployed to manage user access and is typically placed at the network edge to facilitate authentication for web and API services, making it a public-facing service by design.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An unauthenticated vulnerability in Oracle Access Manager's authentication engine could allow an attacker to gain complete control of the system. This issue is easily exploitable over the network and has a critical severity score, indicating significant potential impact.

  • Access Manager vulnerability allows full system takeover.
  • Critical vulnerability impacts authentication and access control.
  • Confirm relevance and potential exposure to Oracle Access Manager.

Attack Path

How an attacker could exploit the issue

An attacker could compromise Oracle Access Manager by sending specially crafted network requests, as the Authentication Engine component is exposed via HTTP. This vulnerability, which requires no authentication, can lead to a complete takeover of the Access Manager system, impacting confidentiality, integrity, and availability.

  • Attacker needs network access.
  • Vulnerable component is Authentication Engine.
  • Full system takeover is possible.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access could potentially compromise Oracle Access Manager, leading to a complete takeover of the system. This is possible because the vulnerability is easily exploitable over HTTP, affecting the authentication engine.

  • Oracle Access Manager system.
  • Network access via HTTP.
  • Complete takeover of the system.

Operational Fix

Recommended remediation, mitigation, and detection steps

Technical leaders and system owners should engage their application and platform teams to identify instances of Oracle Access Manager. Given the CVSS score and network-accessible nature of this vulnerability, prioritize confirming exposure and business criticality to accurately assess risk. This will inform an immediate plan for remediation, which may involve vendor coordination or temporary risk reduction measures in consultation with your security and network teams.

  • Application and platform teams own remediation.
  • Verify external access and business criticality first.
  • Plan vendor coordination and risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Access Manager?

Oracle Access Manager is a core component of Oracle Fusion Middleware used for identity and access management. It functions as a gateway that processes authentication requests for enterprise web applications and APIs, ensuring users are verified before accessing protected resources. Because it validates credentials and manages user sessions, it is a critical piece of infrastructure that sits at the center of organizational security controls.

What does CVE-2026-60355 mean for the authentication engine?

This vulnerability affects the Authentication Engine within Oracle Access Manager. It allows an unauthorized user to bypass normal security checks and gain full control over the system. Essentially, a flaw in how the software processes incoming requests permits an attacker to perform administrative actions without needing a valid login, leading to a complete compromise of the platform's confidentiality, integrity, and availability.

How does an attacker trigger this vulnerability?

An attacker exploits this issue by sending specially crafted HTTP requests directly to the Oracle Access Manager server. Because the vulnerability exists within the authentication logic itself, no prior login or valid user credentials are required to initiate the attack. Conversely, requests that do not target the vulnerable Authentication Engine interface or those sent from segments with no network path to the service will not trigger this specific flaw.

Is my organization at risk from this CVE?

According to Halo Surface Signal, Oracle Access Manager is often placed at the network edge to manage authentication for web services, making it inherently public-facing by design. If your instance is reachable via the internet, it is at higher risk of being targeted. You should verify if your deployment is accessible from external networks or if it is restricted to internal traffic, as this determines your immediate visibility to potential threats.

How should I respond to CVE-2026-60355?

Start by identifying all instances of Oracle Access Manager version 12.2.1.4.0 or 14.1.2.1.0 in your environment. Coordinate with your application and platform teams to verify if these systems are internet-facing and determine their business criticality. Once mapped, prioritize applying the latest security patches provided by the vendor. Consult your security team to implement temporary network restrictions or compensating controls while remediation planning is underway.

References