PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60358 Oracle Corporation CVE debrief

The CVE-2026-60358 vulnerability is a critical issue in the Oracle Access Manager product of Oracle Fusion Middleware, specifically in the Authentication Engine component. It affects versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability allows unauthenticated attackers with network access via HTTP to easily exploit the product and potentially impact additional products. Successful attacks can result in the takeover of Oracle Access Manager. The CVSS 3.1 Base Score is 10.0, indicating a Critical severity level with impacts on Confidentiality, Integrity, and Availability. Organizations should be aware of the potential risks and implement necessary mitigations. This vulnerability has not been modified since its publication on 2026-07-21T22:17:39.057Z.

Vendor
Oracle Corporation
Product
Oracle Access Manager
CVSS
CRITICAL 10
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-28
Advisory published
2026-07-21
Advisory updated
2026-07-28

Who should care

Organizations using Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 should prioritize patching this vulnerability. Security teams and administrators responsible for Oracle Fusion Middleware and Access Manager should be aware of the potential risks and implement necessary mitigations. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Technical summary

The CVE-2026-60358 vulnerability is a critical issue in the Oracle Access Manager product of Oracle Fusion Middleware, specifically in the Authentication Engine component. It affects versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability allows unauthenticated attackers with network access via HTTP to easily exploit the product and potentially impact additional products. Successful attacks can result in the takeover of Oracle Access Manager. The CVSS 3.1 Base Score is 10.0, indicating a Critical severity level with impacts on Confidentiality, Integrity, and Availability.

Defensive priority

Critical vulnerability in Oracle Access Manager allows unauthenticated network attackers to compromise the product, potentially impacting additional products.

Recommended defensive actions

  • Apply vendor patches or updates for Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0.
  • Implement compensating controls, such as network segmentation or access restrictions, to limit exposure.
  • Monitor for suspicious activity and implement exception tracking for potential scope change impacts.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE-2026-60358 vulnerability affects Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0. It allows unauthenticated attackers with network access via HTTP to compromise the product, with potential scope change impacting additional products. The vulnerability has a CVSS 3.1 Base Score of 10.0, indicating a Critical severity level. The CVE record was published on 2026-07-21T22:17:39.057Z and has not been modified since then. Defenders should verify the affected scope and implement necessary mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-60358 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-60358

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-60358 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60358

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.