Summary
CVE-2026-73940 is a critical, easily exploitable vulnerability in the Authentication Engine component of Oracle Access Manager (part of Oracle Fusion Middleware). It allows an unauthenticated, network-based attacker with access via the T3 or IIOP protocols to compromise Oracle Access Manager and potentially achieve complete takeover of the product. The flaw carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: A flaw in the Authentication Engine component of Oracle Access Manager that permits an attacker to bypass authentication and interact with the underlying platform without credentials.
- Trigger conditions: The vulnerability is reachable by any attacker who can send requests to the affected server over the T3 or IIOP protocols; no authentication or user interaction is required.
- Attack vector: Network — the issue is remotely exploitable over T3/IIOP without requiring privileges or user interaction, and Oracle rates it as easily exploitable.
- Impact: Successful exploitation can result in complete compromise (full takeover) of Oracle Access Manager, with high impact to confidentiality, integrity, and availability.
Affected software
- Oracle Access Manager 12.2.1.4.0
- Oracle Access Manager 14.1.2.1.0
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided by Oracle in the September 2026 Critical Security Patch Update for the affected Oracle Access Manager releases (12.2.1.4.0 and 14.1.2.1.0).
- If patching cannot be applied immediately: Restrict or disable network exposure of the T3 and IIOP protocols on Oracle Access Manager / WebLogic-hosted environments — these should never be reachable from untrusted networks or the public internet — and monitor for anomalous T3/IIOP traffic as a compensating control until the patch is deployed.

