Oracle has disclosed CVE-2026-73962, a critical authentication-engine vulnerability in Oracle Access Manager that lets a low-privileged network attacker read and modify data across the identity broker and reach beyond it into connected products.
What Is It
CVE-2026-73962 is a vulnerability in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. Oracle describes it as easily exploitable: an attacker with low privileges and network access over HTTPS can compromise Oracle Access Manager without any user interaction.
The CVSS 3.1 base score is 9.6 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N. Confidentiality and integrity impacts are both High; availability is unaffected; the scored impact is on data, not on the availability of the service itself. The scope is Changed, meaning the blast radius extends past the vulnerable component.
Why It Matters
Oracle Access Manager is an authentication and single sign-on broker. A flaw in its Authentication Engine sits directly on the trust path that other applications rely on. Oracle explicitly warns that while the vulnerability resides in Oracle Access Manager, attacks may significantly impact additional products; the scope change reflected in the CVSS vector.
Successful exploitation allows unauthorized creation, deletion, or modification of critical data, or of all data accessible to Oracle Access Manager, plus unauthorized read access to critical data or complete access to all Oracle Access Manager accessible data. In practical terms, that amounts to broad read and write control over data the identity layer can reach.
The low privilege requirement is the sharpest edge here. Oracle's advisory does not state that administrative access is required, which suggests an authenticated foothold able to reach the HTTPS interface may be sufficient; though Oracle does not specify which privileges an attacker needs.
The CISA Known Exploited Vulnerabilities catalog does not list this CVE, so active exploitation is not confirmed at this time.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Access Manager (Oracle Fusion Middleware)
- Component: Authentication Engine
- Affected supported versions: 12.2.1.4.0 and 14.1.2.1.0
Patch Status
The CVE was published 2026-09-15 with a vulnerability status of "Received," meaning NVD analysis is still pending. The sole reference supplied is an Oracle security alert URL for September 2026; its slug does not follow Oracle's usual security-alerts naming, so treat the specific link as unverified and navigate to Oracle's security alerts index to locate the governing advisory. Oracle's advisory, once identified, is the authoritative source for fix availability and patch identifiers. No specific remediation instructions or required-action deadline are present in the supplied data; consult the Oracle advisory directly before planning deployment.
Sources
- Oracle Security Alert (September 2026), as supplied, link unverified, https://www.oracle.com/security-alerts/cspusep2026.html
- NVD, CVE-2026-73962, https://nvd.nist.gov/vuln/detail/CVE-2026-73962
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog