PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73926 Oracle CVE debrief

A high-severity vulnerability exists in Oracle Access Manager, affecting versions 12.2.1.4.0 and 14.1.2.1.0. This easily exploitable vulnerability allows high-privileged attackers with network access via HTTP to compromise Oracle Access Manager, potentially impacting additional products. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical or all accessible data within Oracle Access Manager.

Vendor
Oracle
Product
Access Manager
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-21
Advisory published
2026-09-15
Advisory updated
2026-09-21

Who should care

Oracle Access Manager administrators, security teams responsible for Oracle Fusion Middleware, and IT personnel managing access management systems should assess exposure and prioritize patching or mitigation efforts.

Why it matters

CVE-2026-73926 is a high-severity vulnerability in Oracle Access Manager that requires immediate attention from administrators and security teams. It allows high-privileged attackers with network access to compromise the system, potentially leading to unauthorized data access and modification. Oracle Access Manager instances, particularly versions 12.2.1.4.0 and 14.1.2.1.0, should be assessed for exposure, and patches or mitigations should be applied as soon as possible.

  • Potential unauthorized creation, deletion, or modification of critical data within Oracle Access Manager.
  • Potential unauthorized access to critical data or complete access to all Oracle Access Manager accessible data.
  • Need for verification of current version exposure and application of patches or mitigations.
  • Possible impact on additional products due to scope change.

Technical summary

The vulnerability is in the Authentication Engine component of Oracle Access Manager, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It has a CVSS 3.1 Base Score of 8.7, indicating high severity due to confidentiality and integrity impacts. Exploitation requires high privileges and network access via HTTP. The vulnerability allows high-privileged attackers with network access to compromise Oracle Access Manager, potentially impacting additional products. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical or all accessible data within Oracle Access Manager.

Defensive priority

High priority for Oracle Access Manager administrators and security teams to assess exposure and apply patches or mitigations.

Recommended defensive actions

  • Assess exposure of Oracle Access Manager instances, particularly versions 12.2.1.4.0 and 14.1.2.1.0.
  • Apply patches or mitigations provided by Oracle as soon as possible.
  • Review network access controls to limit high-privileged attacker access via HTTP.
  • Monitor Oracle Access Manager logs for suspicious activity indicative of exploitation attempts.
  • Verify current version exposure and apply patches or mitigations.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, its impacts, and affected versions. Oracle has also released a security advisory related to this vulnerability. Evidence is limited to public sources, and defenders should verify the vulnerability's existence and scope within their environments. Defensive verification tasks include reviewing Oracle Access Manager instances for exposure, particularly versions 12.2.1.4.0 and 14.1.2.1.0, and applying patches or mitigations as soon as possible.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73926 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73926

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73926 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73926

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.