Oracle Access Manager carries a CVSS 9.9 authentication-engine vulnerability that lets a low-privileged remote attacker take over the product, and Oracle warns that attacks may significantly impact additional products beyond it.
What Is It
CVE-2026-73945 is a vulnerability in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. Oracle describes it as easily exploitable: an attacker with low privileges and network access over HTTP can compromise Oracle Access Manager without any user interaction.
The CVSS 3.1 base score is 9.9 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Successful exploitation results in takeover of Oracle Access Manager, with high impact to confidentiality, integrity, and availability.
Why It Matters
The scope is changed (S:C), Oracle notes that while the vulnerability lives in Oracle Access Manager, attacks may significantly impact additional products. That is the difference between a contained product bug and a blast radius that may extend past the vulnerable component.
The exploitability score is 3.1 against an impact score of 6.0. Low attack complexity, network reach over HTTP, and no user interaction requirement mean the only real barrier is holding low-level privileges. Oracle Access Manager is an access-control and single sign-on product; full takeover of that layer undermines the authentication decisions everything downstream depends on.
As of this writing, CVE-2026-73945 does not appear in CISA's Known Exploited Vulnerabilities catalog, so active exploitation is not confirmed. Readers can verify current status against the catalog directly, linked below.
What's Vulnerable
Per Oracle Corporation, the affected supported versions of Oracle Access Manager are:
- 12.2.1.4.0
- 14.1.2.1.0
No affected CPE records were present in the NVD data.
Patch Status
The CVE was published 2026-09-15 and its NVD vulnerability status is "Received," meaning NVD enrichment is not yet complete. The sole reference is Oracle's security alert page, cspusep2026.html, which is the authoritative source for fixed versions and patch availability.
Because the CVE is not currently listed in the CISA KEV catalog, no federal required action or remediation due date applies to it. Organizations running the affected versions should consult Oracle's advisory directly and treat this as urgent given the 9.9 score and scope change.
Sources
- Oracle Security Alert (CSPU September 2026), https://www.oracle.com/security-alerts/cspusep2026.html
- NVD, CVE-2026-73945, https://nvd.nist.gov/vuln/detail/CVE-2026-73945
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog