PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73940 Oracle CVE debrief

CVE-2026-73940 is a critical vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware, specifically in the Authentication Engine component. This vulnerability allows unauthenticated attackers with network access via T3, IIOP to compromise the system, potentially leading to a takeover of Oracle Access Manager. The affected versions are 12.2.1.4.0 and 14.1.2.1.0. Oracle Access Manager administrators and security teams should assess exposure, prioritize remediation, and verify the effectiveness of compensating controls. The evidence from official sources supports the potential for system compromise and data exposure.

Vendor
Oracle
Product
Access Manager
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-21
Advisory published
2026-09-15
Advisory updated
2026-09-21

Who should care

Oracle Access Manager administrators, security teams, and IT personnel responsible for managing and securing Oracle Fusion Middleware deployments should be aware of this vulnerability. They should assess exposure, prioritize remediation, and verify the effectiveness of compensating controls. The vulnerability's impact on the organization depends on the specific use of Oracle Access Manager and the potential for system compromise and data exposure.

Why it matters

CVE-2026-73940 is a critical vulnerability in Oracle Access Manager that allows unauthenticated attackers to compromise the system. Oracle Access Manager administrators and security teams should assess exposure, prioritize remediation, and verify the effectiveness of compensating controls. The evidence from official sources supports the potential for system compromise and data exposure.

  • Potential system compromise and takeover of Oracle Access Manager.
  • Exposure of sensitive data due to confidentiality impact.
  • Integrity impact leading to unauthorized modifications.
  • Availability impact leading to service disruptions.

Technical summary

The vulnerability in Oracle Access Manager's Authentication Engine allows unauthenticated attackers with network access via T3, IIOP to compromise the system, potentially leading to a takeover of Oracle Access Manager. The CVSS 3.1 Base Score is 9.8, indicating a critical severity level. The affected versions are 12.2.1.4.0 and 14.1.2.1.0. There is no evidence of exploitation in the wild, but defenders should verify the affected versions and apply patches or mitigations as necessary. The vulnerability's technical details are based on official sources, including the CVE Program and NIST NVD.

Defensive priority

High priority for Oracle Access Manager administrators and security teams.

Recommended defensive actions

  • Review and apply Oracle's security patches for Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0.
  • Restrict network access to Oracle Access Manager to minimize the attack surface.
  • Monitor Oracle Access Manager systems for suspicious activity.
  • Perform a thorough review of the affected systems and assess the potential impact.
  • Verify the effectiveness of compensating controls for exposed systems.
  • Track exceptions and retest remediated assets.
  • Close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in Oracle Access Manager, its impact, and affected versions. The vulnerability has a CVSS 3.1 Base Score of 9.8, indicating a critical severity level. There is no evidence of exploitation in the wild, but defenders should verify the affected versions and apply patches or mitigations as necessary. Official sources, including the CVE Program and NIST NVD, confirm the vulnerability's existence and provide guidance on remediation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73940 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73940

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73940 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73940

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.