External risk intelligence

Oracle Access Manager Authentication Engine Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-73940

Oracle Access Manager is an identity and access management solution designed to be a public-facing entry point for authentication and web services. Because it sits at the network edge to manage authentication, it is fundamentally designed for internet-facing deployment to support remote access and identity services.

Authentication Bypass

Oracle Access Manager

12.2.1.4.014.1.2.1.0

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Access Manager, a component within Oracle Fusion Middleware. This issue, if exploited, could allow an unauthenticated attacker to gain complete control over the Oracle Access Manager system. The potential impact involves significant breaches of confidentiality, integrity, and availability.

  • Attackers can take over Oracle Access Manager.
  • Key entry point for secure access is compromised.
  • Confirm if Oracle Access Manager is in use.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could reach Oracle Access Manager over the network using T3 or IIOP protocols. By targeting the Authentication Engine, an attacker could potentially compromise the entire Oracle Access Manager system. This could lead to a full takeover of the access management solution.

  • Attacker has network access.
  • Vulnerable Authentication Engine component.
  • Risk of full system takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access could compromise Oracle Access Manager, potentially leading to a full takeover of the system. This means an attacker could gain complete control over the authentication and access management functionalities provided by Oracle Access Manager.

  • Access management system compromised.
  • Unauthenticated network access.
  • Takeover of Oracle Access Manager.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Oracle Access Manager product component is likely managed by a combination of platform, infrastructure, and security teams due to its role in authentication and network access. The first critical step is to inventory all instances of Oracle Access Manager, confirm their exposure to the network and business criticality, and identify the designated owner for remediation planning.

  • Application and platform teams own the issue.
  • Verify network reachability and asset criticality first.
  • Plan remediation based on confirmed exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Access Manager?

Oracle Access Manager is a core component of Oracle Fusion Middleware used to manage digital identities and secure access to applications. It acts as a gateway that verifies user credentials and enforces authentication policies across an organization's software environment, ensuring that only authorized users can reach protected resources.

What does CVE-2026-73940 mean?

This CVE represents a critical security weakness involving improper authentication (CWE-287) and missing authentication for critical functions (CWE-306). Essentially, the software fails to verify who is requesting access, allowing an unauthorized person to bypass security controls and potentially gain full control of the system.

How does an attacker trigger this vulnerability?

An attacker triggers this flaw by sending specifically crafted network traffic via the T3 or IIOP protocols to the Authentication Engine component. It does not require a legitimate username or password, nor does it require the attacker to have an existing account on the system to initiate the attack.

Is my system at risk if it is not exposed to the internet?

Halo Surface Signal indicates that Oracle Access Manager is typically deployed as a public-facing entry point for authentication, which often puts it at the network edge. While internet-facing instances are at the highest risk, any system reachable via the internal network using T3 or IIOP protocols could also be targeted by an attacker who has gained a foothold inside your perimeter.

What should I do first to address this threat?

Start by performing a comprehensive inventory to locate every instance of Oracle Access Manager running in your environment. Once identified, work with your platform and security teams to determine if those instances are running the affected versions and evaluate their network reachability to prioritize your response efforts.

References