Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-60358: Oracle Access Manager: Unauthorized Access via HTTP
CVE-2026-60358
CVE-2026-60358
Summary
The Oracle Access Manager software has a security weakness that allows hackers to access the system without a password. This could lead to the entire system being taken over. If you're using versions 12.2.1.4.0 or 14.1.2.1.0, you should update to a fixed version to protect your system.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| oracle corporation | oracle access manager | 12.2.1.4.0 |
Original title
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily explo...
Original description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
mitre CVSS3.1
10.0
- https://www.oracle.com/security-alerts/cpujul2026.html vendor-advisory
Published: 21 Jul 2026 · Updated: 25 Jul 2026 · First seen: 24 Jul 2026