Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60358

CVE-2026-60358: Oracle Access Manager Auth Bypass Flaw

CVE-2026-60358 is a critical authentication bypass vulnerability in Oracle Access Manager that allows unauthenticated attackers to take over the system. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-60358 Overview

CVE-2026-60358 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. The flaw affects supported versions 12.2.1.4.0 and 14.1.2.1.0. An unauthenticated attacker with network access via HTTP can compromise Oracle Access Manager without user interaction. Successful exploitation results in complete takeover of Oracle Access Manager and produces a scope change that impacts additional integrated products. Oracle disclosed the issue in the Oracle Security Alert July 2026.

Critical Impact

Unauthenticated remote attackers can take over Oracle Access Manager over HTTP, with cascading impact on federated applications relying on it for single sign-on and authentication.

Affected Products

  • Oracle Access Manager 12.2.1.4.0
  • Oracle Access Manager 14.1.2.1.0
  • Downstream Oracle Fusion Middleware applications integrated with Oracle Access Manager (scope change)

Discovery Timeline

  • 2026-07-21 - CVE-2026-60358 published to NVD
  • 2026-07-21 - Last updated in NVD database
  • July 2026 - Oracle Security Alert published by Oracle

Technical Details for CVE-2026-60358

Vulnerability Analysis

The vulnerability resides in the Authentication Engine of Oracle Access Manager (OAM), the component responsible for verifying identity claims and issuing session tokens for federated Oracle Fusion Middleware applications. An unauthenticated attacker reaches the flaw over HTTP without prior credentials, privileges, or user interaction. Exploitation yields full takeover of OAM, including its ability to issue and validate authentication artifacts.

Oracle marks the issue with a scope change, meaning the compromise extends beyond OAM itself to any product that trusts OAM as its authentication broker. Because OAM commonly fronts business-critical Oracle Fusion Middleware workloads, a single successful attack can cascade into downstream applications, session data, and identity assertions.

EPSS currently places the exploitation probability at 0.486% (39.023 percentile), and no public exploit or CISA KEV listing exists at the time of publication. Oracle has not released technical root cause detail beyond the advisory in the July 2026 Critical Patch Update.

Root Cause

Oracle attributes the flaw to the Authentication Engine component of Oracle Access Manager. Oracle has not published the underlying CWE class or code-level root cause. The advisory language — unauthenticated network exploitation resulting in product takeover with scope change — is consistent with pre-authentication logic flaws in identity broker components handling untrusted HTTP input.

Attack Vector

The attack vector is network based over HTTP. The attacker requires reachability to the OAM authentication endpoints exposed by Oracle Fusion Middleware. No credentials, tokens, or user interaction are needed. Because OAM endpoints are frequently exposed to internet-facing reverse proxies to support single sign-on flows, the exposed attack surface can be substantial in real deployments.

No verified proof-of-concept code is currently available. Refer to the Oracle Security Alert July 2026 for authoritative technical detail as Oracle updates it.

Detection Methods for CVE-2026-60358

Indicators of Compromise

  • Unexpected HTTP requests to Oracle Access Manager authentication endpoints (for example /oam/server/, /oamfed/, /oam/services/rest/) from unfamiliar source addresses.
  • Anomalous creation or modification of OAM administrative sessions, agent registrations, or policy objects outside of change windows.
  • New or unexpected outbound connections from OAM managed servers, or spawned child processes under the WebLogic or OAM runtime user.
  • Authentication assertions issued to downstream Fusion Middleware apps without a corresponding legitimate login event.

Detection Strategies

  • Alert on unauthenticated HTTP requests to OAM endpoints that deviate from baseline URI patterns, user agents, or request bodies.
  • Correlate WebLogic access logs, OAM audit logs, and downstream SSO application logs to identify assertions without matching upstream authentications.
  • Monitor OAM administrative APIs and configuration stores for unauthorized policy, partner, or agent registration changes.

Monitoring Recommendations

  • Ingest OAM audit logs, WebLogic access logs, and reverse-proxy logs into a central analytics platform and retain them long enough to support incident response.
  • Baseline normal request volumes and error rates against OAM endpoints and alert on statistical deviations.
  • Continuously monitor process execution, file writes, and network egress on OAM managed server hosts for post-exploitation behavior.

How to Mitigate CVE-2026-60358

Immediate Actions Required

  • Apply the fixes from the Oracle Critical Patch Update for July 2026 to Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0 deployments.
  • Restrict internet exposure of OAM administrative and authentication endpoints to trusted networks and reverse proxies with strict allowlists.
  • Rotate OAM administrative credentials, signing keys, and agent shared secrets after patching to invalidate any material an attacker could have captured.
  • Review OAM policy, partner, and agent configurations for unauthorized modifications introduced before patching.

Patch Information

Oracle addresses CVE-2026-60358 in the July 2026 Critical Patch Update. Consult the Oracle Security Alert July 2026 for the specific patch identifiers, prerequisites, and installation order applicable to Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0. Apply patches in a validated non-production environment first, then roll forward to production.

Workarounds

  • Place OAM behind a web application firewall with rules that restrict access to authentication and administrative endpoints by source address and method.
  • Terminate OAM administrative interfaces on internal network segments only and require VPN or bastion access.
  • Enforce network segmentation between OAM managed servers and downstream Fusion Middleware applications to limit blast radius from scope-change exploitation.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.