SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61065 2026-07-21

CVE-2026-61065: Critical Unauthenticated Takeover in Oracle Access Manager

"A critical (CVSS 9.8) vulnerability in Oracle Access Manager lets an unauthenticated attacker fully compromise the product over the network via HTTP, with no user interaction required."

A critical (CVSS 9.8) vulnerability in Oracle Access Manager lets an unauthenticated attacker fully compromise the product over the network via HTTP, with no user interaction required.

What Is It

CVE-2026-61065 is a vulnerability in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. Per Oracle's advisory, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful exploitation can result in complete takeover of the product.

The flaw carries a CVSS 3.1 base score of 9.8 (CRITICAL). Its vector, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflects network attack vector, low attack complexity, no privileges required, and no user interaction, with high impact to confidentiality, integrity, and availability.

Why It Matters

Oracle Access Manager is an authentication and single sign-on gateway, so a full takeover undermines the very system enterprises rely on to broker access. Because the vulnerability requires no authentication, no user interaction, and only network HTTP access, the barrier to exploitation is minimal; reflected in the maximum exploitability sub-score of 3.9. Compromise of an identity broker of this kind can cascade into the applications and resources it protects.

What's Vulnerable

The affected product is Oracle Access Manager (Oracle Fusion Middleware), specifically the Authentication Engine component. Oracle lists the following supported versions as affected:

Patch Status

Oracle addressed this vulnerability in its Critical Patch Update of July 2026. Administrators should apply the fixes referenced in the Oracle Critical Patch Update Advisory (July 2026). No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed in the provided source material.

Sources