External risk intelligence

Oracle Access Manager Authentication Engine Vulnerability Allows Unauthorized Data Access

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-73962

Oracle Access Manager is an identity management and access control solution. By design, such systems are typically deployed as public-facing identity portals or authentication gateways to manage user access, making them intended for network exposure as part of their core function.

Oracle Access Manager

12.2.1.4.014.1.2.1.0

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Access Manager, a product used for managing user access and authentication. This issue could allow a low-privileged attacker to gain unauthorized access, potentially impacting critical data and systems beyond the Access Manager itself. The main concern is confirming relevance and exposure, given the potential for significant impact.

  • Unauthorized access to sensitive data is possible.
  • It affects identity and access management systems.
  • Confirm relevance and exposure to critical data.

Attack Path

How an attacker could exploit the issue

An attacker with network access and low privileges can target the Oracle Access Manager's Authentication Engine. This vulnerability allows them to bypass security controls and gain unauthorized access to critical data or modify existing data within the system, potentially impacting other connected Oracle products.

  • Network access and low privileges required.
  • Vulnerability triggered via HTTPS.
  • Unauthorized data access and modification risk.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a low-privileged attacker with network access via HTTPS could compromise Oracle Access Manager, potentially leading to unauthorized modifications or complete access to critical data managed by the system.

  • Critical data managed by Oracle Access Manager.
  • Via network access over HTTPS.
  • Unauthorized access or modification of data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Oracle Access Manager likely falls under the purview of application owners and potentially platform or infrastructure teams, given its role in authentication and potential impact on other Oracle products. The immediate first step is to locate all instances of the affected Oracle Access Manager versions within your environment, assess their exposure (particularly to external networks), confirm business criticality, and identify the specific asset owner responsible for remediation. This information will inform a prioritized plan for addressing the vulnerability.

  • Application owners should manage remediation.
  • Verify network exposure and asset criticality.
  • Plan and coordinate vendor-supported fixes.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Access Manager?

Oracle Access Manager is a core component of Oracle Fusion Middleware designed to handle enterprise identity management and authentication. It serves as a centralized gateway that verifies user identities and controls access permissions for various integrated applications, acting as a critical security layer that mediates how users log in and what data they can interact with across an organization.

What does CWE-284 mean for CVE-2026-73962?

CVE-2026-73962 is categorized under CWE-284, which stands for Improper Access Control. This weakness means the Authentication Engine in the software fails to correctly restrict or verify the permissions associated with a user's request. Because of this flaw, a low-privileged user can perform actions or access information that should be blocked, essentially bypassing the security boundaries intended to protect the system's data integrity.

How is this vulnerability triggered?

The vulnerability is triggered when an attacker with low-level network access sends specific requests to the Authentication Engine via HTTPS. It requires the ability to communicate with the service over the network. It is not triggered by internal administrative actions or local console access, but rather by utilizing the interface meant for authentication traffic.

Do I need to worry if my system is internal?

Halo Surface Signal indicates that Oracle Access Manager is typically deployed as a public-facing identity portal, which increases its risk profile. Even if your specific instance is hosted internally, the nature of the software often involves connectivity to other enterprise systems. You should evaluate if the service is reachable from untrusted network segments, as this impacts the likelihood of an attacker successfully reaching the Authentication Engine.

What should I do first to address this?

Your first step is to perform an inventory of your environment to identify all instances of Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0. Once identified, confirm which instances are currently in use, determine the business impact of those assets, and identify the owners responsible for them. This preparation allows your team to coordinate the application of vendor-supplied patches effectively once you verify your specific configuration.

References