PatchSiren cyber security CVE debrief
CVE-2026-46812 Oracle Corporation CVE debrief
A vulnerability was discovered in Oracle Access Manager, a product of Oracle Fusion Middleware, specifically in the Authentication Engine component. The affected versions are 12.2.1.4.0 and 14.1.2.1.0. This vulnerability is easily exploitable by an unauthenticated attacker with network access via HTTP, potentially compromising Oracle Access Manager. Successful attacks require human interaction from a person other than the attacker and may significantly impact additional products. The vulnerability can result in unauthorized update, insert, or delete access to some Oracle Access Manager accessible data, as well as unauthorized read access to a subset of Oracle Access Manager accessible data.
- Vendor
- Oracle Corporation
- Product
- Oracle Access Manager
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-17
Who should care
Organizations using Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 should prioritize patching this vulnerability to prevent potential unauthorized access and data manipulation.
Technical summary
The vulnerability in Oracle Access Manager has a CVSS 3.1 Base Score of 6.1, indicating a medium severity level. The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N), showing that the vulnerability allows for Confidentiality and Integrity impacts. The vulnerability is in the Authentication Engine component, and successful attacks require human interaction. This vulnerability is easily exploitable by an unauthenticated attacker with network access via HTTP, potentially compromising Oracle Access Manager. The affected versions are 12.2.1.4.0 and 14.1.2.1.0.
Defensive priority
Medium priority should be given to patching this vulnerability due to its medium CVSS score and potential impact on data integrity and confidentiality.
Recommended defensive actions
- Apply the patches provided by Oracle for the affected versions of Oracle Access Manager.
- Implement compensating controls such as monitoring and access restrictions.
- Conduct inventory checks to ensure all instances of Oracle Access Manager are identified and patched.
- Consider enhancing authentication and authorization mechanisms for Oracle Access Manager.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE record was published on 2026-06-17T10:53:58.777Z and was last modified on 2026-06-17T20:37:49.057Z. The NVD entry is currently Analyzed. The vulnerability affects Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0. Successful attacks require human interaction from a person other than the attacker and may significantly impact additional products.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46812 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46812
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46812 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46812
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspujun2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.