External risk intelligence

Oracle Access Manager Authentication Engine Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-73946

Oracle Access Manager is a core identity and access management component designed to provide authentication and gateway services. As a fundamental identity portal and edge authentication service, it is commonly deployed in internet-facing configurations to manage access for users and applications.

Oracle Access Manager

12.2.1.4.014.1.2.1.0

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Access Manager, a component of Oracle Fusion Middleware that handles authentication. This issue, if exploited, could allow a highly privileged attacker to compromise the system, potentially impacting other connected products. The severity of this vulnerability indicates a significant risk to both confidentiality, integrity, and availability.

  • Authentication system vulnerability.
  • High impact on access control.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker with high-level privileges could exploit this vulnerability by sending a crafted request over the network to the Oracle Access Manager's Authentication Engine. Because this component is often exposed to the internet, an attacker could potentially compromise the system without needing direct access to a user's device. Successful exploitation could lead to a complete takeover of the Oracle Access Manager, potentially impacting other connected products.

  • Attacker needs administrative access.
  • Network access via HTTP is sufficient.
  • Results in takeover of the manager.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Oracle Access Manager could allow a highly privileged attacker with network access to take over the system. This means an attacker could potentially control user access, alter authentication processes, and affect other integrated products by compromising this central access control point.

  • Oracle Access Manager system compromised.
  • Attacker gains network access via HTTP.
  • Full system takeover is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

Determining the precise ownership for this Oracle Access Manager vulnerability requires identifying the specific teams managing your identity and access management (IAM) infrastructure, likely involving both platform and security operations. The immediate first step is to inventory all instances of Oracle Access Manager, confirm their exposure to the network, assess their criticality to business operations, and then engage the accountable system owner to plan a coordinated remediation effort.

  • IAM or Platform team owns the issue.
  • Verify network reachability and business impact.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Access Manager?

Oracle Access Manager is a critical component within the Oracle Fusion Middleware suite. It functions as an identity and access management solution that handles authentication and provides gateway services for users and applications. Organizations use it to centralize how people sign in and to control what resources they can access across their enterprise environment.

What is the vulnerability in CVE-2026-73946?

This vulnerability is classified as an improper access control issue (CWE-284). In simple terms, the authentication engine does not properly restrict certain high-level commands. Because of this flaw, the software fails to adequately verify the permissions of a request, allowing a highly privileged user to perform actions that should be restricted, potentially leading to a full system takeover.

How can an attacker trigger this vulnerability?

An attacker needs existing high-level administrative credentials and network access to the system. They trigger the flaw by sending a specially crafted HTTP request to the Authentication Engine. It is important to note that this does not involve standard user actions; the attack specifically relies on the abuse of existing administrative privileges to bypass security boundaries.

Why should I care if my systems use Oracle Access Manager?

Halo Surface Signal indicates that Oracle Access Manager is often deployed in internet-facing configurations because it acts as a primary edge authentication service for many applications. If your instance is reachable from the internet, the potential for a high-privileged attacker to compromise this central identity hub creates a significant risk to your entire connected infrastructure.

What should I do first to address this CVE?

Start by identifying all deployed instances of Oracle Access Manager within your network. Work with your IAM or platform engineering teams to verify which of these instances are accessible over the network. Once you have a clear inventory and understand their business criticality, coordinate with the responsible system owners to prioritize and plan your remediation steps.

References