External risk intelligence

Oracle Access Manager Authentication Engine Vulnerability Allows Unauthorized Data Access and Service Disruption

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-71163

Oracle Access Manager is a centralized identity and access management solution. As an authentication engine, it is designed to be public-facing or sit at the network edge to manage authentication for web applications and services, making it a critical, internet-reachable component in standard deployment patterns.

Denial of Service

Oracle Access Manager

12.2.1.4.014.1.2.1.0

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Access Manager, a key component for managing user authentication and access. This issue could allow unauthorized individuals to gain access to sensitive data and disrupt services, potentially impacting a wide range of connected systems.

  • Access manager flaw impacts authentication and data.
  • Significant access control and data integrity risk.
  • Confirm relevance and understand potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could gain unauthorized access to Oracle Access Manager through the network by exploiting a vulnerability in its Authentication Engine. This allows a low-privileged attacker to compromise the system, potentially leading to unauthorized data modification, data access, or denial of service for Oracle Access Manager and other connected products.

  • Network access required.
  • Vulnerability in Authentication Engine.
  • Unauthorized data access or modification.

Live Threat

Current exploitation, exposure, and threat context

A low-privileged attacker with network access could exploit this vulnerability to gain unauthorized access to critical data or all data accessible by Oracle Access Manager. This could also lead to unauthorized modifications or a partial denial of service, impacting the availability of the system.

  • Critical data and Oracle Access Manager accessible data.
  • Network access via HTTP to the authentication engine.
  • Unauthorized data access, modification, or partial denial of service.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given the Oracle Access Manager's role as a central authentication engine, the platform or infrastructure team is likely responsible for its maintenance. The initial step involves identifying all instances of the affected product, verifying their network exposure and business criticality, and then confirming the accountable owner before planning remediation.

  • Identify and confirm accountable owners.
  • Verify network exposure and business criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Access Manager?

Oracle Access Manager is a central identity and access management component within Oracle Fusion Middleware. It serves as an authentication engine, responsible for verifying user identities and controlling access across web applications and integrated services. Organizations use it to enforce security policies and manage authentication workflows for enterprise software.

What does CVE-2026-71163 mean technically?

This vulnerability is classified as CWE-284, which refers to Improper Access Control. Essentially, the Authentication Engine fails to properly restrict what an attacker can do within the system. Because of this weakness, a low-privileged user can bypass standard security boundaries to read, modify, or delete sensitive data managed by the platform, or cause a partial denial of service.

How is this vulnerability triggered?

The flaw is triggered when an attacker with low-level network access sends specific HTTP requests to the Oracle Access Manager Authentication Engine. It is important to note that this does not require a high-privileged account to initiate; however, the attack must be able to reach the authentication component over the network to attempt exploitation.

Do I need to worry about this if my system is internal?

Yes, you should evaluate your setup. Halo Surface Signal indicates that Oracle Access Manager is often deployed as a public-facing service at the network edge to manage authentication for external applications. Even if you consider your specific instance internal, its role as a centralized security gate makes it a high-value target for any attacker who has gained a foothold inside your network perimeter.

What is the first step if I run affected Oracle software?

Begin by creating an inventory of your environment to identify any instances running versions 12.2.1.4.0 or 14.1.2.1.0. Once identified, map these instances to their respective business owners, assess their network reachability, and confirm their criticality to your operations. This foundational work is necessary to prioritize and coordinate a timely remediation plan with your infrastructure teams.

References