External risk intelligence

Oracle Access Manager Authentication Engine Vulnerability Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-73947

Oracle Access Manager is an identity and access management solution designed to be positioned at the network perimeter to handle authentication for web applications and services. Because it is a public-facing identity portal by design and accepts unauthenticated HTTP requests, it is inherently exposed to the public internet in standard deployment patterns.

Authentication Bypass

Oracle Access Manager

12.2.1.4.014.1.2.1.0

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability found in Oracle Access Manager, a component used for authentication within Oracle Fusion Middleware. The weakness, if exploited, could allow an unauthorized attacker to completely take over the system. The main concern is confirming if our deployment is relevant and potentially exposed.

  • Unauthorized system takeover is possible.
  • Critical component is exposed to external threats.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could target Oracle Access Manager by sending a network request over HTTP. Since no authentication is required to reach the Authentication Engine component, an unauthenticated user can trigger the vulnerability. A successful attack allows the attacker to completely take over the Oracle Access Manager system.

  • No authentication or network access required.
  • Triggered by sending an HTTP request.
  • Complete takeover of the system.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access could compromise Oracle Access Manager, potentially leading to a full takeover of the system. This could affect the confidentiality, integrity, and availability of the access management service.

  • Access Manager system data at risk.
  • Attacker could gain network access.
  • Complete system takeover may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Oracle Access Manager component of Oracle Fusion Middleware is the likely target, suggesting responsibility may lie with application owners or platform teams managing identity and access solutions. The first practical step is to identify all instances of Oracle Access Manager, confirm their network reachability and business criticality, and then locate the accountable owner to plan a risk-based remediation.

  • Identify and confirm ownership of affected instances.
  • Verify network exposure and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Access Manager?

Oracle Access Manager is a core component of Oracle Fusion Middleware used for identity and access management. It acts as a gateway that handles user authentication and authorization for web-based applications and services, ensuring that only verified users can access specific resources.

What does CWE-287 and CWE-306 mean for CVE-2026-73947?

These codes identify weaknesses in how the software handles authentication. CWE-287 refers to improper authentication, while CWE-306 points to a missing authentication for a critical function. Together, they explain why the system fails to properly verify users before allowing them to access or control sensitive parts of the Authentication Engine.

How is this vulnerability triggered?

An attacker triggers the vulnerability by sending a specially crafted HTTP request to the Authentication Engine. Because this component incorrectly processes these requests without requiring valid login credentials, the attack does not require any prior user access or permission to the system.

Is my Oracle Access Manager deployment relevant?

Halo Surface Signal indicates that Oracle Access Manager is often deployed at the network perimeter to serve public-facing identity portals. Because this software is designed to accept unauthenticated HTTP requests from the internet by default, it is highly likely to be reachable by unauthorized parties.

What should I do if I run this software?

Begin by creating an inventory of all Oracle Access Manager instances in your environment. Confirm which versions are running, assess their network accessibility, and identify the team responsible for their maintenance to prioritize a plan for applying vendor-supplied security updates.

References