Sceawere
Vulnerability Detail
CVE-2026-61065Updated Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Access Manager Authentication Compromise
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Access Manager
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-07-21T22:18:37.313Z",
"pubdate": "2026-07-21T22:18:37.313Z",
"executiveSummary": "This vulnerability concerns a critical security flaw within the Authentication Engine component of Oracle Access Manager, part of the Oracle Fusion Middleware stack.\nThe vulnerability is characterized by its high severity, carrying a CVSS 3.1 base score of 9.8, indicating the potential for total system compromise.\nThe flaw allows an unauthenticated remote attacker to gain full control over the Oracle Access Manager instance without requiring any user interaction or valid credentials.\nBy leveraging network access via HTTP, an attacker can exploit the Authentication Engine to bypass established security controls.\nSuccessful exploitation results in the complete loss of confidentiality, integrity, and availability, effectively granting the attacker administrative-level capabilities within the affected middleware environment.\nAffected products include Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0.\nGiven the nature of Oracle Access Manager as an identity and access management solution, this compromise poses a severe risk to the security posture of the entire downstream infrastructure that relies on it for authentication and authorization services.",
"technicalDetails": "The vulnerability resides within the Authentication Engine component of Oracle Access Manager, which is responsible for verifying the identity of users attempting to access protected resources.\nThe root cause of this vulnerability lies in the improper handling of authentication requests by the component, allowing an unauthenticated remote attacker to interact with the engine in a way that leads to unauthorized authentication or system takeover.\nBecause the vulnerability is exploitable via HTTP, it is accessible to any entity with network connectivity to the affected service, requiring no specialized access or authentication tokens.\nThe attack vector relies on sending specially crafted HTTP requests to the Oracle Access Manager Authentication Engine. Due to the lack of sufficient input validation or authentication checks at this interface, the system processes these requests as if they were legitimate, potentially allowing the attacker to bypass the authentication flow entirely.\nUpon successful exploitation, the attacker can leverage the compromised session or elevated privileges to execute arbitrary commands or manipulate system state. As the Authentication Engine is a core component, an attacker who successfully gains control at this level can effectively manage or override security policies, access sensitive user credentials stored within the system, or manipulate the identity propagation mechanisms used across the organization's middleware infrastructure.\nThis is classified as a 'takeover' vulnerability because it allows an attacker to achieve full administrative control over the application. Once the Authentication Engine is subverted, the attacker can impersonate any user, including administrative accounts, which facilitates lateral movement and deep persistence within the Fusion Middleware environment.\nThe technical impact is comprehensive (C:H/I:H/A:H), meaning the attacker can read sensitive data (Confidentiality), modify or delete configuration and data (Integrity), and disrupt service availability (Availability).\nAffected versions are strictly limited to 12.2.1.4.0 and 14.1.2.1.0. Exploitation does not require elevated privileges or local interaction, and the attack complexity is considered low, making it a highly attractive target for automated scanning and exploitation tools that target publicly reachable middleware instances."
}