SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60326 2026-07-21

CVE-2026-60326: Critical Unauthenticated Bypass in Oracle Access Manager

"A critical, easily exploitable flaw in Oracle Access Manager's Authentication Engine lets unauthenticated attackers over HTTP fully compromise the product's data, earning a CVSS 3.1 base score of 9.1."

A critical, easily exploitable flaw in Oracle Access Manager's Authentication Engine lets unauthenticated attackers over HTTP fully compromise the product's data, earning a CVSS 3.1 base score of 9.1.

What Is It

CVE-2026-60326 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, no privileges, no user interaction, and low attack complexity, yielding a base score of 9.1 (CRITICAL).

Why It Matters

Oracle Access Manager is an authentication and single sign-on gateway, so a pre-authentication compromise strikes at the identity layer protecting downstream applications. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, or all Oracle Access Manager–accessible data, as well as unauthorized read access up to complete access to all such data. The vulnerability carries HIGH confidentiality and integrity impact; availability is not affected per the published metrics.

What's Vulnerable

According to the NVD record, the affected product is Oracle Access Manager (vendor: Oracle Corporation), specifically the Authentication Engine component. Supported versions listed as affected are:

Patch Status

The vulnerability was published on 2026-07-21 with NVD status "Received." Oracle addressed it in the July 2026 Critical Patch Update; administrators should consult Oracle's security alert and apply the corresponding fixes for the affected versions. No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed by KEV in the available source material.

Sources