PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-71163 Oracle CVE debrief

A critical vulnerability exists in Oracle Access Manager, affecting versions 12.2.1.4.0 and 14.1.2.1.0. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Access Manager, potentially impacting additional products. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, unauthorized access to critical data, and partial denial of service.

Vendor
Oracle
Product
Access Manager
CVSS
CRITICAL 9.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-21
Advisory published
2026-09-15
Advisory updated
2026-09-21

Who should care

Oracle Access Manager administrators, security teams, and IT personnel responsible for ensuring the security and integrity of Oracle Access Manager installations should assess exposure and prioritize remediation.

Why it matters

This critical vulnerability in Oracle Access Manager requires immediate attention from administrators to prevent potential exploitation and data compromise.

  • Potential unauthorized creation, deletion, or modification of critical data
  • Potential unauthorized access to critical data
  • Partial denial of service (partial DOS) of Oracle Access Manager

Technical summary

The vulnerability is in the Authentication Engine component of Oracle Access Manager, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It has a CVSS 3.1 Base Score of 9.9, indicating critical severity. The CVSS Vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, unauthorized access to critical data, and partial denial of service. Oracle Access Manager administrators should prioritize remediation to prevent potential exploitation.

Defensive priority

High priority remediation is recommended for Oracle Access Manager administrators to prevent potential exploitation.

Recommended defensive actions

  • Review and apply Oracle's security patches for Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0
  • Restrict network access to Oracle Access Manager to only necessary personnel
  • Monitor Oracle Access Manager for suspicious activity
  • Verify the integrity of Oracle Access Manager data
  • Conduct a thorough review of system logs to identify potential security incidents
  • Implement compensating controls, such as additional monitoring or access restrictions, for exposed systems
  • Track exceptions and retest remediated assets to ensure the vulnerability is fully resolved

Evidence notes

The vulnerability is described in the CVE Program record and NVD vulnerability detail pages. Oracle has also provided a vendor advisory. Evidence from these sources indicates that the Authentication Engine component of Oracle Access Manager is affected. However, specific details about the vulnerability, such as its root cause or potential exploits, are limited. Defenders should verify the integrity of Oracle Access Manager data and review system logs for suspicious activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-71163 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-71163

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-71163 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-71163

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.