PatchSiren cyber security CVE debrief
CVE-2026-60358 Oracle Corporation CVE debrief
The CVE-2026-60358 vulnerability is a critical issue in the Oracle Access Manager product of Oracle Fusion Middleware, specifically in the Authentication Engine component. It affects versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability allows unauthenticated attackers with network access via HTTP to easily exploit the product and potentially impact additional products. Successful attacks can result in the takeover of Oracle Access Manager. The CVSS 3.1 Base Score is 10.0, indicating a Critical severity level with impacts on Confidentiality, Integrity, and Availability. Organizations should be aware of the potential risks and implement necessary mitigations. This vulnerability has not been modified since its publication on 2026-07-21T22:17:39.057Z.
- Vendor
- Oracle Corporation
- Product
- Oracle Access Manager
- CVSS
- CRITICAL 10
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-28
Who should care
Organizations using Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 should prioritize patching this vulnerability. Security teams and administrators responsible for Oracle Fusion Middleware and Access Manager should be aware of the potential risks and implement necessary mitigations. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Technical summary
The CVE-2026-60358 vulnerability is a critical issue in the Oracle Access Manager product of Oracle Fusion Middleware, specifically in the Authentication Engine component. It affects versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability allows unauthenticated attackers with network access via HTTP to easily exploit the product and potentially impact additional products. Successful attacks can result in the takeover of Oracle Access Manager. The CVSS 3.1 Base Score is 10.0, indicating a Critical severity level with impacts on Confidentiality, Integrity, and Availability.
Defensive priority
Critical vulnerability in Oracle Access Manager allows unauthenticated network attackers to compromise the product, potentially impacting additional products.
Recommended defensive actions
- Apply vendor patches or updates for Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0.
- Implement compensating controls, such as network segmentation or access restrictions, to limit exposure.
- Monitor for suspicious activity and implement exception tracking for potential scope change impacts.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE-2026-60358 vulnerability affects Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0. It allows unauthenticated attackers with network access via HTTP to compromise the product, with potential scope change impacting additional products. The vulnerability has a CVSS 3.1 Base Score of 10.0, indicating a Critical severity level. The CVE record was published on 2026-07-21T22:17:39.057Z and has not been modified since then. Defenders should verify the affected scope and implement necessary mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-60358 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-60358
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-60358 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60358
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cpujul2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.