PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73946 Oracle CVE debrief

A critical vulnerability exists in Oracle Access Manager, specifically in the Authentication Engine component of Oracle Fusion Middleware. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0. An attacker with high privileges and network access via HTTP can easily exploit this vulnerability, potentially leading to a takeover of Oracle Access Manager. The scope of the vulnerability is not limited to Oracle Access Manager, as successful attacks may significantly impact additional products.

Vendor
Oracle
Product
Access Manager
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-21
Advisory published
2026-09-15
Advisory updated
2026-09-21

Who should care

System administrators and security teams responsible for Oracle Access Manager instances should assess exposure and apply remediation to prevent potential exploitation. This includes teams managing Oracle Fusion Middleware, particularly those with high-privileged access and network connectivity. The vulnerability's impact on additional products requires careful consideration and verification of system integrity.

Why it matters

A critical vulnerability in Oracle Access Manager requires immediate attention from system administrators and security teams to assess exposure and apply remediation.

  • Potential takeover of Oracle Access Manager systems by high-privileged attackers.
  • Significant impact on additional products if the vulnerability is exploited.
  • High priority for remediation due to the critical CVSS score of 9.1.
  • Verification of system integrity and data security is necessary.

Technical summary

The vulnerability in Oracle Access Manager's Authentication Engine component can be exploited by high-privileged attackers with network access via HTTP, potentially leading to a takeover of the system. The affected versions are 12.2.1.4.0 and 14.1.2.1.0. The scope of the vulnerability is not limited to Oracle Access Manager, as successful attacks may significantly impact additional products. The vulnerability has a critical CVSS score of 9.1, indicating high confidentiality, integrity, and availability impacts. System administrators and security teams should assess exposure and apply remediation to prevent potential exploitation.

Defensive priority

High priority should be given to assessing exposure and applying remediation to Oracle Access Manager instances, particularly those with high-privileged access and network connectivity.

Recommended defensive actions

  • Assess exposure of Oracle Access Manager instances, particularly those with high-privileged access and network connectivity.
  • Apply remediation as provided by Oracle for the affected versions.
  • Monitor for potential exploitation attempts and anomalous activity.
  • Verify the integrity of Oracle Access Manager systems and data.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, its impact, and affected versions. Oracle has also released a vendor advisory regarding this vulnerability. The vulnerability affects Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0, and an attacker with high privileges and network access via HTTP can easily exploit it. The scope of the vulnerability is not limited to Oracle Access Manager, as successful attacks may significantly impact additional products. Defenders should verify system integrity,

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73946 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73946

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73946 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73946

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.