PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35314 Oracle Corporation CVE debrief

A vulnerability was discovered in Oracle Access Manager, specifically in the Web Server Plugin component. This vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0. It is easily exploitable by unauthenticated attackers with network access via HTTP, potentially leading to unauthorized data access and partial denial of service. The vulnerability has a CVSS 3.1 Base Score of 7.3, indicating high severity. Organizations should prioritize patching this vulnerability to prevent potential exploitation.

Vendor
Oracle Corporation
Product
Oracle Access Manager
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-17
Original CVE updated
2026-06-17
Advisory published
2026-06-17
Advisory updated
2026-06-17

Who should care

Organizations using Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 should prioritize patching this vulnerability to prevent potential exploitation. This is particularly important for operators, platform administrators, vulnerability management teams, and security teams who may be impacted by the vulnerability.

Technical summary

The vulnerability in Oracle Access Manager's Web Server Plugin allows unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized update, insert or delete access to some Oracle Access Manager accessible data, unauthorized read access to a subset of Oracle Access Manager accessible data, and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Access Manager. The CVSS 3.1 Base Score is 7.3, indicating high severity.

Defensive priority

High priority should be given to patching this vulnerability due to its high CVSS score and the potential for exploitation.

Recommended defensive actions

  • Apply the latest patches from Oracle Corporation
  • Review and update access controls for Oracle Access Manager
  • Monitor for suspicious activity related to Oracle Access Manager
  • Consider implementing additional security measures such as Web Application Firewalls
  • Verify and enforce secure configurations for Oracle Access Manager
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-06-17T10:40:23.573Z and last modified on 2026-06-17T19:54:48.410Z. The NVD entry is currently Analyzed. This information is based on the provided source corpus and may not reflect the full scope of the vulnerability. Further verification is recommended.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-35314 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-35314

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-35314 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-35314

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.