A critical vulnerability, CVE-2026-35313, has been identified in Oracle Access Manager, part of Oracle Fusion Middleware. The flaw resides in the Authentication Engine component, affecting versions 12.2.1.4.0 and 14.1.2.1.0. This vulnerability is easily exploitable, allowing a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation could result in full takeover of Oracle Access Manager, with potential impact extending to other products due to scope changes. The CVSS 3.1 base score of 9.9 reflects the high severity, with implications for confidentiality, integrity, and availability. Organizations utilizing the affected versions of Oracle Access Manager should prioritize applying the latest security patches provided by Oracle. Until patches are implemented, network access to the affected systems should be restricted, and additional security measures such as intrusion detection systems and network segmentation should be considered. Users are advised to review Oracle's official advisory for detailed mitigation steps and ensure all systems are updated to secure versions.
CRITICAL
CVSS 9.9
CVE-2026-35313
2026-08-28
Critical Vulnerability in Oracle Access Manager (CVE-2026-35313)
A critical vulnerability in Oracle Access Manager allows low-privileged attackers to take over the system via HTTP. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. CVSS score 9.9, requiring immediate mitigation.