Summary
CVE-2026-73941 is a vulnerability in the Authentication Engine of Oracle Access Manager, a component of Oracle Fusion Middleware, that allows an unauthenticated, network-based attacker to gain unauthorized access to sensitive data. Oracle rates the flaw as easily exploitable, requiring no authentication or user interaction, and assigns it a CVSS v3.1 base score of 8.6 (High).
Technical details
- Root cause: A flaw in the Authentication Engine component of Oracle Access Manager.
- Trigger conditions: No privileges or user interaction are required; the attacker only needs network access to the exposed Oracle Access Manager instance.
- Attack vector: Network, over HTTP, with low attack complexity (AV:N/AC:L/PR:N/UI:N).
- Impact: Per Oracle’s own characterization, successful exploitation can result in "unauthorized access to critical data or complete access to all Oracle Access Manager accessible data." The CVSS vector reflects a scope change (S:C) with a high confidentiality impact and no impact to integrity or availability.
Affected software
- Oracle Access Manager 12.2.1.4.0
- Oracle Access Manager 14.1.2.1.0
Severity
- CVSS v3.1 Base Score: 8.6 (High)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Apply the Oracle security patch addressing CVE-2026-73941 for the affected Oracle Access Manager releases (12.2.1.4.0 and 14.1.2.1.0), as published in Oracle’s security alert.
- If patching cannot be applied immediately: Restrict network exposure of Oracle Access Manager endpoints to trusted networks only, and monitor Oracle Access Manager logs for anomalous authentication activity until the patch can be deployed.

