Cyber & AI intelligence
Wasteland.
Briefs indexed2663
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-71163 2026-09-15

CVE-2026-71163: Critical Scope-Changing Flaw in Oracle Access Manager

"A CVSS 9.9 vulnerability in the Oracle Access Manager Authentication Engine lets a low-privileged network attacker read and modify all data the product can access, degrade its availability, and, per Oracle, potentially…"

A CVSS 9.9 vulnerability in the Oracle Access Manager Authentication Engine lets a low-privileged network attacker read and modify all data the product can access, degrade its availability, and, per Oracle, potentially affect additional products beyond it.

What Is It

CVE-2026-71163 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. Oracle describes it as easily exploitable: an attacker with low privileges and network access over HTTP can compromise Oracle Access Manager without any user interaction.

The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L, yielding a base score of 9.9 (CRITICAL). The scope-change flag (S:C) is what pushes this into near-maximum territory; Oracle states that while the flaw lives in Access Manager, attacks may significantly impact additional products.

Successful exploitation can result in unauthorized creation, deletion, or modification of critical data or all Oracle Access Manager accessible data; unauthorized access to critical data or complete access to all Oracle Access Manager accessible data; and the ability to cause a partial denial of service against Oracle Access Manager.

Why It Matters

Oracle Access Manager is an authentication and single sign-on broker. A flaw in its Authentication Engine that, according to Oracle's impact description, can yield read and write access to the data the product handles, and that Oracle indicates may extend across a security scope boundary into other products, sits directly on the trust path that downstream applications depend on. The low attack complexity and the requirement of only low privileges (rather than none) suggest that a relatively modest authenticated foothold may be sufficient.

As of 2026-09-15, this CVE does not appear in the CISA Known Exploited Vulnerabilities catalog (linked below), so no KEV-mandated remediation deadline applies. No confirmed active exploitation has been publicly reported at the time of writing.

What's Vulnerable

Patch Status

The CVE was published on 2026-09-15 with an NVD status of Received, meaning NVD analysis is not yet complete.

The specific Oracle advisory page carried in the reference data (listed below) does not follow Oracle's published naming conventions; Oracle Critical Patch Updates use the form cpu<month><year>.html and are released on a fixed January/April/July/October cycle, while out-of-band Security Alerts use the form alert-cve-<id>.html. Treat that URL as unverified: it may be a typo for a Critical Patch Update page, or the advisory may not yet be posted at that location. Until Oracle's own advisory can be confirmed, administrators should locate the authoritative fix through Oracle's security alerts index and My Oracle Support rather than relying on the linked page, and should apply the resulting patch or workaround to both affected version branches.

Sources