Summary
CVE-2026-71133 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. It allows an unauthenticated attacker with network access via HTTP to fully compromise the product, and Oracle notes the attack may significantly impact additional products due to a scope change. The flaw carries the maximum CVSS v3.1 base score of 10.0 (Critical).
Technical details
- Root cause: a flaw in the Authentication Engine component of Oracle Access Manager.
- Trigger conditions: exploitable without authentication and without any user interaction.
- Attack vector: network access over HTTP; Oracle rates the vulnerability as "easily exploitable."
- Impact: successful exploitation results in complete takeover of Oracle Access Manager, with full loss of confidentiality, integrity, and availability. Oracle also flags a "scope change," indicating the impact may extend beyond Access Manager to other integrated products.
Affected software
- Oracle Access Manager 12.2.1.4.0
- Oracle Access Manager 14.1.2.1.0
Severity
CVSS v3.1 Base Score: 10.0 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: apply the Oracle Critical Patch Update that addresses CVE-2026-71133 for Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0, as detailed in Oracle’s security advisory.
- If immediate patching is not possible: restrict network access to Oracle Access Manager interfaces to trusted networks only, and monitor authentication logs for anomalous or unauthenticated activity until the patch can be applied.

