PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60358 Oracle Corporation CVE debrief

The CVE-2026-60358 vulnerability is a critical issue in the Oracle Access Manager product of Oracle Fusion Middleware, specifically in the Authentication Engine component. It affects versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability allows unauthenticated attackers with network access via HTTP to easily exploit the product and potentially impact additional products. Successful attacks can result in the takeover of Oracle Access Manager. The CVSS 3.1 Base Score is 10.0, indicating a Critical severity level with impacts on Confidentiality, Integrity, and Availability. Organizations should be aware of the potential risks and implement necessary mitigations. This vulnerability has not been modified since its publication on 2026-07-21T22:17:39.057Z.

Vendor
Oracle Corporation
Product
Oracle Access Manager
CVSS
CRITICAL 10
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-28
Advisory published
2026-07-21
Advisory updated
2026-07-28

Who should care

Organizations using Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 should prioritize patching this vulnerability. Security teams and administrators responsible for Oracle Fusion Middleware and Access Manager should be aware of the potential risks and implement necessary mitigations. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Technical summary

The CVE-2026-60358 vulnerability is a critical issue in the Oracle Access Manager product of Oracle Fusion Middleware, specifically in the Authentication Engine component. It affects versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability allows unauthenticated attackers with network access via HTTP to easily exploit the product and potentially impact additional products. Successful attacks can result in the takeover of Oracle Access Manager. The CVSS 3.1 Base Score is 10.0, indicating a Critical severity level with impacts on Confidentiality, Integrity, and Availability.

Defensive priority

Critical vulnerability in Oracle Access Manager allows unauthenticated network attackers to compromise the product, potentially impacting additional products.

Recommended defensive actions

  • Apply vendor patches or updates for Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0.
  • Implement compensating controls, such as network segmentation or access restrictions, to limit exposure.
  • Monitor for suspicious activity and implement exception tracking for potential scope change impacts.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE-2026-60358 vulnerability affects Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0. It allows unauthenticated attackers with network access via HTTP to compromise the product, with potential scope change impacting additional products. The vulnerability has a CVSS 3.1 Base Score of 10.0, indicating a Critical severity level. The CVE record was published on 2026-07-21T22:17:39.057Z and has not been modified since then. Defenders should verify the affected scope and implement necessary mitigations.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:39.057Z and has not been modified since then.