Summary
CVE-2026-73958 is a vulnerability in the Authentication Engine component of Oracle Access Manager (part of Oracle Fusion Middleware). It allows an unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager, with Oracle’s advisory describing the impact as a potential complete takeover of the product. The flaw carries a CVSS v3.1 base score of 8.1 (High).
Technical details
- Root cause: a flaw in the Authentication Engine component of Oracle Access Manager that can be abused over the network.
- Trigger conditions: Oracle rates the attack complexity as High, indicating exploitation requires specific conditions or additional information beyond simply reaching the service over HTTP.
- Attack vector: Network access via HTTP; no authentication or user interaction is required.
- Impact: successful exploitation can result in high impact to confidentiality, integrity, and availability, with Oracle describing the worst case as complete compromise/takeover of Oracle Access Manager.
Affected software
- Oracle Access Manager 12.2.1.4.0
- Oracle Access Manager 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 8.1 (High)
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s September 2026 Critical Security Patch Update for the affected Oracle Access Manager versions (12.2.1.4.0 and 14.1.2.0.0).
- If patching cannot be applied immediately: restrict network exposure of Oracle Access Manager endpoints to trusted networks only, and monitor authentication logs for anomalous or unexpected authentication flows until the patch can be deployed.

