SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60355 2026-07-21

Oracle Access Manager Authentication Bypass — CVE-2026-60355

"A critical, unauthenticated vulnerability in Oracle Access Manager's Authentication Engine lets a remote attacker fully take over the product over HTTP."

A critical, unauthenticated vulnerability in Oracle Access Manager's Authentication Engine lets a remote attacker fully take over the product over HTTP.

What Is It

CVE-2026-60355 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. Per Oracle's advisory, it is an "easily exploitable" flaw that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful exploitation can result in a complete takeover of the product. It carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, and no user interaction required.

Why It Matters

The CVSS breakdown reflects the worst-case profile: high impact to confidentiality, integrity, and availability, reachable remotely with no authentication and no user interaction. Because Oracle Access Manager brokers authentication and access control for enterprise applications, its takeover puts the identity layer that other systems trust directly in an attacker's hands. There is no CISA KEV entry in the supplied material, so active exploitation is not confirmed by that source at this time.

What's Vulnerable

According to the NVD record, the affected product is Oracle Access Manager (Oracle Fusion Middleware), component Authentication Engine. The supported versions listed as affected are:

Patch Status

The vulnerability is addressed in Oracle's Critical Patch Update for July 2026. Administrators running the affected versions should apply the fixes referenced in that advisory. No separate CISA-mandated required action is present in the supplied source material.

Sources