PatchSiren cyber security CVE debrief
CVE-2026-73947 Oracle CVE debrief
A critical vulnerability exists in Oracle Access Manager, specifically in the Authentication Engine component of Oracle Fusion Middleware. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated attacker with network access via HTTP can easily exploit this vulnerability to compromise Oracle Access Manager, potentially leading to a takeover of the system. The CVSS 3.1 Base Score is 9.8, indicating a high impact on Confidentiality, Integrity, and Availability.
- Vendor
- Oracle
- Product
- Access Manager
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-21
Who should care
Security teams responsible for Oracle Access Manager instances, specifically those using versions 12.2.1.4.0 and 14.1.2.0.0, should assess exposure and apply necessary patches or mitigations to prevent potential exploitation.
Why it matters
A critical vulnerability in Oracle Access Manager requires immediate attention to assess exposure and apply necessary patches or mitigations to prevent potential exploitation.
- Potential takeover of Oracle Access Manager instances by unauthenticated attackers.
- High impact on Confidentiality, Integrity, and Availability due to CVSS 3.1 Base Score of 9.8.
- Need for immediate attention to assess exposure and apply patches or mitigations.
Technical summary
The vulnerability exists in the Authentication Engine component of Oracle Access Manager, affecting versions 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated attacker with network access via HTTP can exploit this vulnerability, potentially leading to a takeover of Oracle Access Manager. The CVSS 3.1 Base Score is 9.8, indicating a high impact on Confidentiality, Integrity, and Availability. The vulnerability allows for easy exploitation, and successful attacks can result in a takeover of Oracle Access Manager. Security teams should assess exposure and apply necessary patches or mitigations to prevent potential exploitation.
Defensive priority
Immediate attention is required to assess exposure and apply necessary patches or mitigations to prevent potential exploitation.
Recommended defensive actions
- Assess exposure of Oracle Access Manager instances, specifically versions 12.2.1.4.0 and 14.1.2.0.0.
- Apply patches or mitigations provided by Oracle to address the vulnerability.
- Monitor network access to Oracle Access Manager instances to prevent potential exploitation.
- Verify that Oracle Access Manager instances are not exposed to unauthorized access.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD vulnerability detail provide information on the affected versions and the CVSS score. Oracle's security alert also provides additional context on the vulnerability. The vulnerability exists in the Authentication Engine component of Oracle Access Manager, affecting versions 12.2.1.4.0 and 14.1.2.0.0. Evidence is limited to public CVE and NVD data. Defenders should verify exposure and apply patches or mitigations accordingly. Additional information may be available from Oracle's security alert.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73947 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73947
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73947 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73947
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspusep2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.