A critical vulnerability in Oracle Access Manager allows a low-privileged, network-based attacker to fully compromise the product and impact adjacent systems, carrying a CVSS 3.1 base score of 9.9.
What Is It
CVE-2026-60333 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is easily exploitable and allows a low-privileged attacker with network access over HTTP to compromise Oracle Access Manager. Successful exploitation can result in a complete takeover of the product. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, reflecting high impacts to confidentiality, integrity, and availability.
Why It Matters
With a base score of 9.9 (CRITICAL), this is among the most severe class of vulnerabilities. The attack requires only low privileges, no user interaction, and can be carried out remotely over the network; a low barrier for exploitation. Critically, the scope is marked as changed: while the vulnerability resides in Oracle Access Manager, Oracle notes that attacks "may significantly impact additional products." As an identity and access management platform, a takeover here can undermine authentication controls across dependent systems.
What's Vulnerable
The affected product is Oracle Access Manager (Oracle Fusion Middleware). Per the NVD record, the affected supported versions are:
- 12.2.1.4.0
- 14.1.2.1.0
The vulnerable component is the Authentication Engine.
Patch Status
Oracle addressed this issue in its July 2026 Critical Patch Update. Organizations running the affected versions should consult the Oracle Critical Patch Update advisory and apply the corresponding fixes. Given the critical severity and low exploitation complexity, patching should be prioritized.
No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed in the provided source material.
Sources
- Oracle Critical Patch Update Advisory (July 2026), https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60333, https://nvd.nist.gov/vuln/detail/CVE-2026-60333