Cyber & AI intelligence
Wasteland.
Briefs indexed2663
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-73945 2026-09-15

CVE-2026-73945: Critical Oracle Access Manager Flaw Allows Full Takeover

"Oracle Access Manager carries a CVSS 9.9 authentication-engine vulnerability that lets a low-privileged remote attacker take over the product, and Oracle warns that attacks may significantly impact additional products…"

Oracle Access Manager carries a CVSS 9.9 authentication-engine vulnerability that lets a low-privileged remote attacker take over the product, and Oracle warns that attacks may significantly impact additional products beyond it.

What Is It

CVE-2026-73945 is a vulnerability in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. Oracle describes it as easily exploitable: an attacker with low privileges and network access over HTTP can compromise Oracle Access Manager without any user interaction.

The CVSS 3.1 base score is 9.9 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Successful exploitation results in takeover of Oracle Access Manager, with high impact to confidentiality, integrity, and availability.

Why It Matters

The scope is changed (S:C), Oracle notes that while the vulnerability lives in Oracle Access Manager, attacks may significantly impact additional products. That is the difference between a contained product bug and a blast radius that may extend past the vulnerable component.

The exploitability score is 3.1 against an impact score of 6.0. Low attack complexity, network reach over HTTP, and no user interaction requirement mean the only real barrier is holding low-level privileges. Oracle Access Manager is an access-control and single sign-on product; full takeover of that layer undermines the authentication decisions everything downstream depends on.

As of this writing, CVE-2026-73945 does not appear in CISA's Known Exploited Vulnerabilities catalog, so active exploitation is not confirmed. Readers can verify current status against the catalog directly, linked below.

What's Vulnerable

Per Oracle Corporation, the affected supported versions of Oracle Access Manager are:

No affected CPE records were present in the NVD data.

Patch Status

The CVE was published 2026-09-15 and its NVD vulnerability status is "Received," meaning NVD enrichment is not yet complete. The sole reference is Oracle's security alert page, cspusep2026.html, which is the authoritative source for fixed versions and patch availability.

Because the CVE is not currently listed in the CISA KEV catalog, no federal required action or remediation due date applies to it. Organizations running the affected versions should consult Oracle's advisory directly and treat this as urgent given the 9.9 score and scope change.

Sources