PatchSiren cyber security CVE debrief
CVE-2026-71163 Oracle CVE debrief
A critical vulnerability exists in Oracle Access Manager, affecting versions 12.2.1.4.0 and 14.1.2.1.0. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Access Manager, potentially impacting additional products. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, unauthorized access to critical data, and partial denial of service.
- Vendor
- Oracle
- Product
- Access Manager
- CVSS
- CRITICAL 9.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-21
Who should care
Oracle Access Manager administrators, security teams, and IT personnel responsible for ensuring the security and integrity of Oracle Access Manager installations should assess exposure and prioritize remediation.
Why it matters
This critical vulnerability in Oracle Access Manager requires immediate attention from administrators to prevent potential exploitation and data compromise.
- Potential unauthorized creation, deletion, or modification of critical data
- Potential unauthorized access to critical data
- Partial denial of service (partial DOS) of Oracle Access Manager
Technical summary
The vulnerability is in the Authentication Engine component of Oracle Access Manager, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It has a CVSS 3.1 Base Score of 9.9, indicating critical severity. The CVSS Vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, unauthorized access to critical data, and partial denial of service. Oracle Access Manager administrators should prioritize remediation to prevent potential exploitation.
Defensive priority
High priority remediation is recommended for Oracle Access Manager administrators to prevent potential exploitation.
Recommended defensive actions
- Review and apply Oracle's security patches for Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0
- Restrict network access to Oracle Access Manager to only necessary personnel
- Monitor Oracle Access Manager for suspicious activity
- Verify the integrity of Oracle Access Manager data
- Conduct a thorough review of system logs to identify potential security incidents
- Implement compensating controls, such as additional monitoring or access restrictions, for exposed systems
- Track exceptions and retest remediated assets to ensure the vulnerability is fully resolved
Evidence notes
The vulnerability is described in the CVE Program record and NVD vulnerability detail pages. Oracle has also provided a vendor advisory. Evidence from these sources indicates that the Authentication Engine component of Oracle Access Manager is affected. However, specific details about the vulnerability, such as its root cause or potential exploits, are limited. Defenders should verify the integrity of Oracle Access Manager data and review system logs for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-71163 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-71163
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-71163 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-71163
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspusep2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.