Oracle Access Manager Unauthenticated Authentication Engine Takeover (CVE-2026-60358)
First seen Jul 24, 2026 · Updated Jul 24, 2026 · CVSS 10
A maximum-severity (CVSS 10.0) vulnerability in Oracle Access Manager's Authentication Engine allows unauthenticated, network-based attackers to fully compromise the identity and access management system. The flaw has a scope change, meaning successful exploitation can cascade to impact other integrated applications and services relying on OAM for authentication.
Technical Analysis
CVE-2026-60358 affects Oracle Fusion Middleware's Access Manager component in versions 12.2.1.4.0 and 14.1.2.1.0, with the flaw residing in the Authentication Engine and reachable over HTTP without authentication (AV:N/AC:L/PR:N/UI:N). The CVSS 3.1 vector indicates a scope change (S:C) with full confidentiality, integrity, and availability impact (C:H/I:H/A:H), consistent with an authentication bypass or takeover primitive that grants an attacker control over the identity provider itself. Because OAM is frequently deployed as a single sign-on and federated authentication gateway, compromise enables lateral movement into any downstream application or service trusting OAM-issued tokens, including internal APIs and management consoles. Organizations that route AI agent authentication, service-to-service API calls, or RAG pipeline access controls through Oracle Access Manager face direct exposure: an attacker taking over OAM could mint or forge valid session tokens to impersonate agents, exfiltrate API keys/credentials stored or brokered through the IAM layer, or hijack agent-to-backend trust relationships. This makes the flaw agent-relevant wherever OAM sits in the identity chain for autonomous or semi-autonomous AI systems.
Affected Systems
Oracle Fusion Middleware - Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0; any downstream applications, APIs, or agent frameworks federated through affected OAM instances via SSO or token-based trust
Indicators of Compromise
- No specific IOCs published at this time; monitor OAM authentication logs for anomalous unauthenticated requests to Authentication Engine endpoints, unexpected admin session creation, and unusual HTTP traffic patterns to OAM login/authn URLs
Remediation Steps
- 1
Apply Oracle Critical Patch Update
Immediately apply the Oracle CPU/patch addressing CVE-2026-60358 for Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0.
- 2
Restrict network exposure
Limit direct network/internet access to OAM authentication endpoints using firewalls, WAF rules, or VPN-only access until patched.
- 3
Audit authentication logs
Review OAM and downstream application logs for anomalous unauthenticated login attempts, session token anomalies, or privilege escalations since disclosure.
- 4
Rotate credentials and tokens
Rotate API keys, service account credentials, and session secrets managed or brokered through OAM, especially those used by automated systems and AI agents.
- 5
Review federated trust relationships
Audit downstream applications and agent frameworks trusting OAM-issued tokens to identify scope of potential compromise (scope-change vulnerability).
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.