Cyber & AI intelligence
Wasteland.
Briefs indexed2663
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-73946 2026-09-15

Oracle Access Manager Hit With Critical Auth Engine Takeover Flaw (CVE-2026-73946)

"A critical vulnerability in the Authentication Engine of Oracle Access Manager allows a network-based attacker with high privileges to fully take over the product and impact adjacent systems through a scope change."

A critical vulnerability in the Authentication Engine of Oracle Access Manager allows a network-based attacker with high privileges to fully take over the product and impact adjacent systems through a scope change.

What Is It

CVE-2026-73946 is a vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware, specifically in the Authentication Engine component. The CVE record describes it as easily exploitable, allowing a high-privileged attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks result in complete takeover of Oracle Access Manager.

It carries a CVSS 3.1 base score of 9.1 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, network attack vector, low attack complexity, no user interaction, and high impact to confidentiality, integrity, and availability (NVD).

Why It Matters

Oracle Access Manager is an identity and access enforcement layer. A takeover of that layer is a takeover of the authentication decisions it makes on behalf of everything sitting behind it.

The CVSS vector confirms a changed scope (S:C). Under Oracle's standard scoping convention, a changed scope on a Fusion Middleware component signals that while the vulnerability resides in Oracle Access Manager, attacks may significantly impact additional products. The blast radius is not contained to the vulnerable component. Confirm the exact scope language and affected downstream products against Oracle's own security alert advisory before relying on it for risk modeling.

The mitigating factor is the privilege requirement (PR:H), an attacker needs high privileges to begin with. That makes this a post-compromise escalation and lateral movement problem rather than a perimeter-breach problem, but it does not lower the impact once the precondition is met.

What's Vulnerable

The affected supported versions listed in the CVE record are:

Vendor: Oracle Corporation. Component: Authentication Engine. Attack path: HTTP.

Patch Status

The CVE was published 2026-09-15 and its NVD status is Received: meaning NVD enrichment analysis is not yet complete (NVD). The CVSS data available is Oracle's own primary assessment.

Because NVD enrichment is still pending, the vendor advisory is the authoritative source for remediation. Administrators running either affected version should go directly to Oracle's security alerts page and locate the advisory covering this release cycle for fixed-version and patch-application guidance, rather than relying on secondhand version mappings.

CVE-2026-73946 does not appear in the CISA Known Exploited Vulnerabilities catalog as of 2026-09-15. Active exploitation is not confirmed, and no KEV-mandated remediation deadline applies at this time.

Sources