criticalZero-Day

Oracle Access Manager Unauthenticated Authentication Engine Takeover

First seen Jul 24, 2026 · Updated Jul 24, 2026 · CVSS 9.8

oracleaccess-managerfusion-middlewareunauthenticated-rceauthentication-bypassidentity-managementagent-relevant

A critical unauthenticated vulnerability (CVE-2026-60355) in Oracle Access Manager's Authentication Engine allows remote attackers to fully compromise the identity and access management system over HTTP with no credentials required. Given the CVSS 9.8 score and full confidentiality, integrity, and availability impact, successful exploitation could grant attackers complete control over enterprise authentication infrastructure. Organizations using Oracle Access Manager for SSO or identity federation are at severe risk of large-scale account takeover and downstream system compromise.

Technical Analysis

CVE-2026-60355 affects Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 within Oracle Fusion Middleware, specifically the Authentication Engine component. The vulnerability is remotely exploitable via HTTP without authentication or user interaction (AV:N/AC:L/PR:N/UI:N), and results in a scope-unchanged compromise with high impact to confidentiality, integrity, and availability (C:H/I:H/A:H). Given the low attack complexity, this flaw likely stems from a logic or validation flaw in authentication token handling, session management, or an access control bypass in the authentication flow, enabling attackers to impersonate users or gain administrative control over the Access Manager instance. Because Oracle Access Manager frequently serves as the centralized identity provider (SSO/federation) for enterprise applications, compromise here can cascade into unauthorized access across all federated systems, including API gateways and backend services. Where AI agent frameworks or RAG pipelines rely on Oracle Access Manager-issued tokens or SSO sessions to authenticate service accounts and retrieve API keys or credentials, this vulnerability could allow attackers to hijack agent identities, exfiltrate secrets, or impersonate autonomous agents to access downstream enterprise systems.

Affected Systems

Oracle Fusion Middleware - Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0; specifically the Authentication Engine component exposed via HTTP endpoints.

Indicators of Compromise

  • No specific IOCs published at this time (vulnerability disclosure without confirmed exploitation indicators)

Remediation Steps

  1. 1

    Apply Oracle Critical Patch Update

    Immediately apply the latest Oracle Critical Patch Update (CPU) addressing CVE-2026-60355 for affected Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0.

  2. 2

    Restrict network exposure

    Limit direct HTTP/network access to Oracle Access Manager endpoints to trusted internal networks or VPN, and place a WAF in front of authentication endpoints to filter anomalous requests.

  3. 3

    Monitor authentication logs

    Review Access Manager authentication and session logs for anomalous unauthenticated access patterns, unexpected privilege escalations, or unusual session creation.

  4. 4

    Rotate credentials and tokens

    Rotate SSO tokens, service account credentials, and API keys tied to Access Manager-authenticated systems, including those used by automated agents or service integrations.

  5. 5

    Implement compensating controls

    If patching cannot be immediately applied, consider isolating the Authentication Engine component or enabling additional multi-factor verification layers external to Access Manager.

CVE / Advisory IDs

CVE-2026-60355

Industries Most Exposed

financial serviceshealthcaregovernmenttechnologytelecommunicationsretailmanufacturing

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.