Oracle Access Manager Authentication Engine Takeover Vulnerability
First seen Jul 24, 2026 · Updated Jul 24, 2026 · CVSS 9.9
A critical vulnerability (CVSS 9.9) in Oracle Access Manager's Authentication Engine allows a low-privileged attacker with only network access via HTTP to fully compromise the identity and access management system. Due to a scope change, successful exploitation can impact additional connected products beyond Oracle Access Manager itself, making this a high-priority patching target for any organization relying on Oracle Fusion Middleware for SSO and access control.
Technical Analysis
CVE-2026-60333 affects the Authentication Engine component of Oracle Access Manager within Oracle Fusion Middleware, impacting versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability is remotely exploitable over HTTP with low attack complexity and requires only low privileges and no user interaction, per the CVSS vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The scope change (S:C) indicates that compromising the Authentication Engine can cascade into full control over downstream applications and services that rely on OAM for SSO/federated authentication, effectively enabling full takeover of the identity broker and any resources trusting its tokens. Organizations using Oracle Access Manager as an identity provider for AI agent orchestration platforms, RAG pipelines, or agent-to-service authentication should treat this as a direct risk, since a compromised authentication layer could allow attackers to mint or hijack tokens used by autonomous agents to access APIs, secrets, and internal tools, leading to broader credential and data exposure across agent-integrated systems.
Affected Systems
Oracle Access Manager (Oracle Fusion Middleware) versions 12.2.1.4.0 and 14.1.2.1.0, specifically the Authentication Engine component, and any downstream applications or services relying on OAM for SSO/authentication.
Indicators of Compromise
- No public IOCs available at time of disclosure; monitor Oracle Critical Patch Update advisories and OAM authentication logs for anomalous low-privilege authentication requests, unexpected token issuance, or unusual HTTP traffic to OAM endpoints.
Remediation Steps
- 1
Apply Oracle Critical Patch Update
Immediately apply the official Oracle security patch for CVE-2026-60333 for Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0.
- 2
Restrict network access
Limit HTTP access to Oracle Access Manager endpoints to trusted networks and enforce strict network segmentation while patches are being validated and deployed.
- 3
Audit authentication logs
Review OAM authentication and session logs for anomalous low-privilege access patterns or unexpected authentication engine behavior.
- 4
Rotate credentials and tokens
Rotate SSO tokens, API keys, and service credentials tied to OAM-federated applications and any AI agent integrations that rely on OAM for authentication.
- 5
Enable enhanced monitoring
Deploy WAF rules and enhanced logging around OAM HTTP endpoints to detect and block exploitation attempts targeting the Authentication Engine.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.