SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60358 2026-07-21

CVE-2026-60358: Critical Unauthenticated Takeover in Oracle Access Manager

"A maximum-severity (CVSS 10.0) flaw in Oracle Access Manager's Authentication Engine lets an unauthenticated attacker take over the product over HTTP, with impact spilling into other integrated systems."

A maximum-severity (CVSS 10.0) flaw in Oracle Access Manager's Authentication Engine lets an unauthenticated attacker take over the product over HTTP, with impact spilling into other integrated systems.

What Is It

CVE-2026-60358 is a critical vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware, specifically its Authentication Engine component. The flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks can result in a complete takeover of the product. Oracle assigns it a CVSS 3.1 Base Score of 10.0 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, no privileges or user interaction required, low attack complexity, and high confidentiality, integrity, and availability impacts.

Why It Matters

Oracle Access Manager is a centralized identity and single sign-on platform, making it a high-value target. Critically, the vulnerability carries a scope change (S:C): while the flaw resides in Oracle Access Manager, attacks may significantly impact additional products beyond it. Combined with unauthenticated network exploitability and full compromise potential, this represents a worst-case scenario; a perfect 10.0 rating that warrants urgent attention.

What's Vulnerable

The affected product is Oracle Access Manager (Oracle Fusion Middleware). The supported versions confirmed affected are:

Patch Status

The vulnerability is addressed in Oracle's Critical Patch Update for July 2026. Organizations running the affected versions should consult the Oracle security alert and apply the corresponding CPU fixes. No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed in the provided source material.

Sources