PatchSiren cyber security CVE debrief
CVE-2026-73926 Oracle CVE debrief
A high-severity vulnerability exists in Oracle Access Manager, affecting versions 12.2.1.4.0 and 14.1.2.1.0. This easily exploitable vulnerability allows high-privileged attackers with network access via HTTP to compromise Oracle Access Manager, potentially impacting additional products. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical or all accessible data within Oracle Access Manager.
- Vendor
- Oracle
- Product
- Access Manager
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-21
Who should care
Oracle Access Manager administrators, security teams responsible for Oracle Fusion Middleware, and IT personnel managing access management systems should assess exposure and prioritize patching or mitigation efforts.
Why it matters
CVE-2026-73926 is a high-severity vulnerability in Oracle Access Manager that requires immediate attention from administrators and security teams. It allows high-privileged attackers with network access to compromise the system, potentially leading to unauthorized data access and modification. Oracle Access Manager instances, particularly versions 12.2.1.4.0 and 14.1.2.1.0, should be assessed for exposure, and patches or mitigations should be applied as soon as possible.
- Potential unauthorized creation, deletion, or modification of critical data within Oracle Access Manager.
- Potential unauthorized access to critical data or complete access to all Oracle Access Manager accessible data.
- Need for verification of current version exposure and application of patches or mitigations.
- Possible impact on additional products due to scope change.
Technical summary
The vulnerability is in the Authentication Engine component of Oracle Access Manager, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It has a CVSS 3.1 Base Score of 8.7, indicating high severity due to confidentiality and integrity impacts. Exploitation requires high privileges and network access via HTTP. The vulnerability allows high-privileged attackers with network access to compromise Oracle Access Manager, potentially impacting additional products. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical or all accessible data within Oracle Access Manager.
Defensive priority
High priority for Oracle Access Manager administrators and security teams to assess exposure and apply patches or mitigations.
Recommended defensive actions
- Assess exposure of Oracle Access Manager instances, particularly versions 12.2.1.4.0 and 14.1.2.1.0.
- Apply patches or mitigations provided by Oracle as soon as possible.
- Review network access controls to limit high-privileged attacker access via HTTP.
- Monitor Oracle Access Manager logs for suspicious activity indicative of exploitation attempts.
- Verify current version exposure and apply patches or mitigations.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, its impacts, and affected versions. Oracle has also released a security advisory related to this vulnerability. Evidence is limited to public sources, and defenders should verify the vulnerability's existence and scope within their environments. Defensive verification tasks include reviewing Oracle Access Manager instances for exposure, particularly versions 12.2.1.4.0 and 14.1.2.1.0, and applying patches or mitigations as soon as possible.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73926 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73926
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73926 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73926
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspusep2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.