A critical, easily exploitable flaw in Oracle Access Manager lets an unauthenticated attacker take full control of the product over the network, carrying a maximum-tier CVSS 3.1 base score of 9.8.
What Is It
CVE-2026-60328 is a vulnerability in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. A successful attack can result in complete takeover of the product. The issue is rated CRITICAL with a CVSS 3.1 base score of 9.8 and the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Why It Matters
The CVSS breakdown reflects the worst-case profile: network attack vector, low attack complexity, no privileges required, and no user interaction, combined with HIGH impact to confidentiality, integrity, and availability. Because Oracle Access Manager handles authentication, a takeover of this component can undermine access control across the systems that depend on it. No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed in the source material.
What's Vulnerable
The affected product is Oracle Access Manager (Oracle Corporation), within Oracle Fusion Middleware. The supported versions listed as affected are:
- 12.2.1.4.0
- 14.1.2.1.0
The vulnerable component is the Authentication Engine.
Patch Status
Oracle addresses this vulnerability in its July 2026 Critical Patch Update. Organizations running the affected versions should consult and apply the fixes from the Oracle Critical Patch Update Advisory referenced below. Given the 9.8 severity and unauthenticated network exploitability, patching should be prioritized. No KEV-mandated remediation deadline was provided in the source material.
Sources
- Oracle Critical Patch Update Advisory – July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60328, https://nvd.nist.gov/vuln/detail/CVE-2026-60328