External risk intelligence

Oracle Access Manager Authentication Engine Vulnerability Allows Takeover

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-60358

Oracle Access Manager is an identity and access management solution designed to handle authentication for enterprise applications. As a gateway component that manages user access, it is typically deployed in public-facing or edge-network roles to facilitate remote or external user authentication.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability impacts Oracle Access Manager, a component within Oracle Fusion Middleware used for managing user authentication. The issue is easily exploitable by unauthenticated attackers over the network, potentially leading to a full takeover of the Access Manager system and significant impacts on other connected products.

  • Unauthenticated attackers can gain full control of access management.
  • It affects a core system for verifying user identities.
  • Confirm relevance and exposure of this critical access flaw.

Attack Path

How an attacker could exploit the issue

An attacker can remotely access Oracle Access Manager over the network without needing any credentials to trigger this vulnerability. Once exploited, it can lead to the complete compromise of the Oracle Access Manager, potentially affecting other connected products.

  • No authentication required for attack.
  • Network access via HTTP to the Authentication Engine.
  • Takeover of Oracle Access Manager and other products.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access via HTTP to take over Oracle Access Manager. When supported, this takeover could impact additional products.

  • Oracle Access Manager.
  • Unauthenticated network access.
  • Complete system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for Oracle Access Manager, likely part of an identity and access management or platform team, should take the lead. The first practical step is to identify all instances of Oracle Access Manager, confirm their accessibility from the network and business criticality, and then engage the accountable owner to plan remediation.

  • Identity and Access Management or Platform teams.
  • Verify Oracle Access Manager instance exposure.
  • Plan and coordinate remediation activities.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Access Manager?

Oracle Access Manager is a centralized identity and access management solution within the Oracle Fusion Middleware suite. It acts as a gateway for enterprise applications, responsible for verifying user identities and enforcing access policies. Because it serves as the gatekeeper for authentication, it is often positioned at the network edge to facilitate seamless access for remote and external users.

How should I understand the security flaw in CVE-2026-60358?

This vulnerability is an authentication flaw within the product's engine. In technical terms, it allows an unauthenticated party to bypass standard security checks. Because the vulnerability involves a scope change, a successful attack does not just compromise the authentication engine itself; it can potentially allow an attacker to gain control over other integrated systems that rely on this service for identity verification.

Do I need to be logged in to trigger this vulnerability?

No. The vulnerability is designed such that an attacker does not require any existing credentials or user accounts to initiate an attempt. Accessing the Authentication Engine over the network via HTTP is sufficient to trigger the issue. Interactions that do not involve reaching the Authentication Engine's network-facing HTTP interface do not trigger this specific vulnerability.

Why is this CVE considered relevant to my network perimeter?

Halo Surface Signal indicates that Oracle Access Manager is typically deployed in public-facing or edge-network roles to manage external user authentication. Because the attack vector is network-based, systems that are exposed to the internet are at the highest risk, as they are reachable by unauthorized remote actors without requiring internal network access.

What is the first step for teams managing this software?

The immediate priority is to locate all instances of Oracle Access Manager within your environment to determine which are active. Once identified, evaluate whether these instances are accessible from the network. After confirming the footprint and potential exposure, coordinate with your platform or identity management teams to schedule and apply the necessary security updates.

References