Cyber & AI intelligence
Wasteland.
Briefs indexed2663
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-83001 2026-09-15

CVE-2026-83001: Critical Oracle Access Manager Takeover Flaw in Fusion Middleware

"Oracle disclosed a CVSS 9.1 vulnerability in the Oracle Access Manager Authentication Engine that allows a network-based attacker with high privileges to fully take over the product and impact adjacent systems."

Oracle disclosed a CVSS 9.1 vulnerability in the Oracle Access Manager Authentication Engine that allows a network-based attacker with high privileges to fully take over the product and impact adjacent systems.

What Is It

CVE-2026-83001 is a critical vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware, specifically in the Authentication Engine component. Oracle describes it as easily exploitable: an attacker with network access over HTTP and high privileges on the target can compromise Oracle Access Manager. Successful exploitation results in complete takeover of Oracle Access Manager.

The CVSS 3.1 vector is AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, producing a base score of 9.1 (CRITICAL) with high confidentiality, integrity, and availability impact. The record was published 2026-09-15 by Oracle's security alert channel and currently carries NVD status "Received."

Why It Matters

The scope is marked CHANGED. Oracle explicitly notes that while the flaw lives in Oracle Access Manager, attacks may significantly impact additional products. That matters because Access Manager is an authentication and SSO broker; a component that other applications trust to make identity decisions. Takeover of that trust anchor does not stay contained to one host.

Attack complexity is LOW and no user interaction is required. The mitigating factor is the high privilege requirement (PR:H), which means an attacker needs elevated access before exploitation, making this most dangerous as a post-compromise escalation and lateral-movement path rather than an initial intrusion vector.

There is no CISA KEV entry for CVE-2026-83001 in the supplied data, so active exploitation is not confirmed at this time.

What's Vulnerable

Per Oracle, the supported affected versions of Oracle Access Manager are:

No CPE data is currently listed in the NVD record.

Patch Status

Oracle published this under its September 2026 security alert. The supplied data contains no specific patch identifier, workaround, or CISA-mandated remediation deadline. Administrators should consult the Oracle security alert page below for the applicable fix for their version.

Sources