criticalZero-Day

Oracle Access Manager Unauthenticated Authentication Engine Takeover (CVE-2026-60358)

First seen Jul 24, 2026 · Updated Jul 24, 2026 · CVSS 10

oracleaccess-managementauthentication-bypassunauthenticated-rcecritical-infrastructureidentity-provideragent-relevant

A maximum-severity (CVSS 10.0) vulnerability in Oracle Access Manager's Authentication Engine allows unauthenticated, network-based attackers to fully compromise the identity and access management system. The flaw has a scope change, meaning successful exploitation can cascade to impact other integrated applications and services relying on OAM for authentication.

Technical Analysis

CVE-2026-60358 affects Oracle Fusion Middleware's Access Manager component in versions 12.2.1.4.0 and 14.1.2.1.0, with the flaw residing in the Authentication Engine and reachable over HTTP without authentication (AV:N/AC:L/PR:N/UI:N). The CVSS 3.1 vector indicates a scope change (S:C) with full confidentiality, integrity, and availability impact (C:H/I:H/A:H), consistent with an authentication bypass or takeover primitive that grants an attacker control over the identity provider itself. Because OAM is frequently deployed as a single sign-on and federated authentication gateway, compromise enables lateral movement into any downstream application or service trusting OAM-issued tokens, including internal APIs and management consoles. Organizations that route AI agent authentication, service-to-service API calls, or RAG pipeline access controls through Oracle Access Manager face direct exposure: an attacker taking over OAM could mint or forge valid session tokens to impersonate agents, exfiltrate API keys/credentials stored or brokered through the IAM layer, or hijack agent-to-backend trust relationships. This makes the flaw agent-relevant wherever OAM sits in the identity chain for autonomous or semi-autonomous AI systems.

Affected Systems

Oracle Fusion Middleware - Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0; any downstream applications, APIs, or agent frameworks federated through affected OAM instances via SSO or token-based trust

Indicators of Compromise

  • No specific IOCs published at this time; monitor OAM authentication logs for anomalous unauthenticated requests to Authentication Engine endpoints, unexpected admin session creation, and unusual HTTP traffic patterns to OAM login/authn URLs

Remediation Steps

  1. 1

    Apply Oracle Critical Patch Update

    Immediately apply the Oracle CPU/patch addressing CVE-2026-60358 for Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0.

  2. 2

    Restrict network exposure

    Limit direct network/internet access to OAM authentication endpoints using firewalls, WAF rules, or VPN-only access until patched.

  3. 3

    Audit authentication logs

    Review OAM and downstream application logs for anomalous unauthenticated login attempts, session token anomalies, or privilege escalations since disclosure.

  4. 4

    Rotate credentials and tokens

    Rotate API keys, service account credentials, and session secrets managed or brokered through OAM, especially those used by automated systems and AI agents.

  5. 5

    Review federated trust relationships

    Audit downstream applications and agent frameworks trusting OAM-issued tokens to identify scope of potential compromise (scope-change vulnerability).

CVE / Advisory IDs

CVE-2026-60358

Industries Most Exposed

financial serviceshealthcaregovernmenttechnologytelecommunicationsretailmanufacturing

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.