Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60326

CVE-2026-60326: Oracle Access Manager Auth Bypass Flaw

CVE-2026-60326 is an authentication bypass vulnerability in Oracle Access Manager affecting versions 12.2.1.4.0 and 14.1.2.1.0. This critical flaw allows unauthorized data access and modification. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-60326 Overview

CVE-2026-60326 is a vulnerability in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. Affected versions are 12.2.1.4.0 and 14.1.2.1.0. The flaw allows an unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager without user interaction. Successful exploitation grants unauthorized read, create, delete, and modify access to all Oracle Access Manager accessible data. Oracle addressed the issue in the July 2026 Critical Patch Update.

Critical Impact

Unauthenticated network attackers can fully compromise the confidentiality and integrity of all data accessible through Oracle Access Manager.

Affected Products

  • Oracle Access Manager 12.2.1.4.0
  • Oracle Access Manager 14.1.2.1.0
  • Oracle Fusion Middleware — Authentication Engine component

Discovery Timeline

  • 2026-07-21 - CVE-2026-60326 published to NVD
  • 2026-07-23 - Last updated in NVD database
  • July 2026 - Oracle releases fix in the Oracle Security Alert July 2026

Technical Details for CVE-2026-60326

Vulnerability Analysis

The vulnerability resides in the Authentication Engine of Oracle Access Manager (OAM), the module responsible for validating credentials and issuing session tokens for federated single sign-on. An unauthenticated remote attacker can send crafted HTTP requests to the OAM endpoint and bypass authentication controls. Successful exploitation results in unauthorized access to protected data and the ability to create, modify, or delete records the OAM instance can reach. Because OAM brokers authentication for downstream Fusion Middleware applications, compromise of the engine can expose identity data and enable lateral movement into applications that rely on OAM tokens. Oracle rates the issue with CVSS Base Score 9.1 for confidentiality and integrity impact; availability is not affected.

Root Cause

Oracle has not published the underlying code defect. Based on the advisory metadata, the flaw is an authentication bypass in the HTTP request-handling path of the Authentication Engine, exploitable without prior credentials or user interaction. See the Oracle Security Alert July 2026 for vendor-provided detail.

Attack Vector

The attack vector is Network (AV:N) over HTTP with low complexity and no privileges or user interaction required. An attacker needs only reachability to the OAM HTTP listener, typically exposed to intranet clients and often to the internet for federated login. Exploitation involves issuing crafted HTTP requests to the Authentication Engine endpoint to obtain unauthorized data access or perform destructive operations against OAM-managed records.

No verified public proof-of-concept is available at the time of writing. Refer to the Oracle Security Alert July 2026 for authoritative technical details.

Detection Methods for CVE-2026-60326

Indicators of Compromise

  • Anomalous HTTP POST or GET requests to Oracle Access Manager Authentication Engine URIs from unexpected source addresses.
  • OAM audit log entries showing successful authentication or data access events without a corresponding credential validation record.
  • Unusual create, modify, or delete operations against OAM identity stores outside normal administrative windows.
  • Spikes in OAM session token issuance from a single client IP or user agent.

Detection Strategies

  • Enable and centralize OAM audit logging, then alert on authentication events lacking a preceding credential validation step.
  • Correlate access logs from the OAM managed server with backend LDAP and database queries to identify orphan sessions.
  • Baseline typical HTTP request patterns to OAM endpoints and flag deviations in method, URI, or body size.

Monitoring Recommendations

  • Forward OAM, WebLogic, and reverse-proxy access logs to a SIEM or data lake for retention and correlation.
  • Monitor egress from OAM hosts for unexpected connections that may indicate post-exploitation data staging.
  • Track file integrity on OAM configuration files and audit changes to identity provider settings.

How to Mitigate CVE-2026-60326

Immediate Actions Required

  • Apply the July 2026 Oracle Critical Patch Update to all Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0 instances.
  • Restrict network access to OAM HTTP endpoints so that only trusted proxies and application tiers can reach the Authentication Engine.
  • Rotate OAM administrative credentials, keystores, and session signing keys if compromise is suspected.
  • Review OAM audit logs for evidence of unauthorized data access dating back to before the patch date.

Patch Information

Oracle released fixes as part of the July 2026 Critical Patch Update. See the Oracle Security Alert July 2026 for the specific patch bundle identifiers for each affected version.

Workarounds

  • Place OAM behind a web application firewall configured to block anomalous requests to Authentication Engine URIs until patching completes.
  • Enforce network segmentation so OAM management and authentication endpoints are not directly reachable from untrusted networks.
  • Increase audit verbosity on OAM to capture full request metadata during the interim period before patch deployment.
bash
# Example: restrict OAM HTTP listener to trusted upstream proxies via iptables
iptables -A INPUT -p tcp --dport 14100 -s 10.0.0.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 14100 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.