External risk intelligence

Oracle Access Manager Authentication Engine Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-73945

Oracle Access Manager is a core identity and access management solution. These systems are typically deployed at the network edge to manage authentication, SSO, and gateway services, making them inherently public-facing or accessible to a wide range of external-facing services by design.

Oracle Access Manager

12.2.1.4.014.1.2.1.0

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A significant vulnerability has been identified within Oracle Access Manager, a component of Oracle Fusion Middleware. This issue, which can be exploited remotely by an attacker with limited privileges, could lead to a complete compromise of the Access Manager system and potentially impact other connected products. The severity of this vulnerability, rated as Critical, underscores the need for awareness and action.

  • A critical flaw impacts Oracle Access Manager.
  • It could allow unauthorized control of the system.
  • Confirm relevance and exposure for Oracle Access Manager.

Attack Path

How an attacker could exploit the issue

An attacker could target Oracle Access Manager via network access using standard HTTP. If successful, the attacker can take over the Access Manager, potentially affecting other connected products.

  • Requires network access and low privileges.
  • Exploits the Authentication Engine component.
  • Leads to complete system takeover.

Live Threat

Current exploitation, exposure, and threat context

A low-privileged attacker with network access could compromise Oracle Access Manager, potentially impacting other connected products. This vulnerability can lead to the complete takeover of the Oracle Access Manager system, affecting its confidentiality, integrity, and availability.

  • Oracle Access Manager system and data.
  • Via network access over HTTP.
  • Complete takeover of the system.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Oracle Access Manager product, specifically its Authentication Engine, is vulnerable to exploitation by a low-privileged attacker with network access via HTTP. This could lead to a complete takeover of the affected Oracle Access Manager instances, with potential impact on other connected products. Technical leaders and security teams should first identify all deployments of Oracle Access Manager, confirm their reachability and business criticality, identify the accountable owner, and then plan remediation based on risk.

  • Application owners should own this issue.
  • Verify network exposure and business criticality.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Access Manager?

Oracle Access Manager is a critical identity and access management solution within the Oracle Fusion Middleware suite. It serves as a centralized gateway to manage user authentication, single sign-on capabilities, and access policies for various enterprise applications. By verifying user identities before granting access to resources, it functions as a foundational security layer for controlling entry to sensitive systems and data.

What does CWE-284 mean for CVE-2026-73945?

The vulnerability is categorized under CWE-284, which stands for Improper Access Control. In the context of CVE-2026-73945, this means the software does not sufficiently restrict unauthorized users from performing sensitive operations. Because the flaw resides in the Authentication Engine, an attacker can bypass intended security checks to manipulate the system, effectively gaining control over functions that should be strictly protected.

How does an attacker trigger CVE-2026-73945?

An attacker initiates the vulnerability by sending specially crafted HTTP requests to the target system. The primary precondition is that the attacker must have network access and possess at least low-privileged credentials for the application. It is important to note that this bug does not require physical access or local system entry; however, simply browsing the application normally or possessing no credentials at all will not trigger this specific flaw.

Is my organization at risk from this vulnerability?

According to Halo Surface Signal, Oracle Access Manager is often deployed at the network edge to handle gateway and authentication tasks, which frequently makes it public-facing by design. Because this CVE is accessible via HTTP, any instance reachable from a network—especially the internet—carries a heightened risk. If your system manages SSO or authentication for external services, you should assume it is a relevant target for this type of network-based attack.

What steps should I take if I run Oracle Access Manager?

Your first step is to perform an inventory to locate every instance of Oracle Access Manager in your environment. Once identified, work with the designated system owners to verify network reachability and determine the business criticality of each instance. Use this information to prioritize patching and mitigation efforts, ensuring that instances with the highest connectivity to untrusted networks are addressed with the greatest urgency.

References