Summary
CVE-2026-73944 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. Oracle describes it as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager, with high impact to confidentiality and integrity. It carries a CVSS v3.1 base score of 9.1 (Critical) and was disclosed via an Oracle Critical Security Patch Update advisory on September 15, 2026.
Technical details
- Root cause: A flaw in the Authentication Engine component of Oracle Access Manager.
- Trigger conditions: No authentication or user interaction is required; the attacker only needs network access to the exposed Oracle Access Manager HTTP interface.
- Attack vector: Network-based, over HTTP, with low attack complexity (AV:N/AC:L/PR:N/UI:N).
- Impact: Successful exploitation can result in unauthorized access to, and modification of, data accessible to Oracle Access Manager (C:H/I:H), with no reported impact to availability (A:N).
Affected software
- Oracle Access Manager 12.2.1.4.0
- Oracle Access Manager 14.1.2.1.0
(Both are part of Oracle Fusion Middleware.)
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Apply the Oracle patches for Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0 provided in Oracle’s September 2026 Critical Security Patch Update advisory.
- If no patch can be applied immediately: Restrict network access to Oracle Access Manager’s HTTP interfaces to trusted sources only, and closely monitor authentication and access logs for anomalous activity until the patch is deployed. Note that broadly blocking HTTP access will disrupt normal single sign-on functionality, so this should be treated as a temporary measure only.

