CVE-2026-35261: Oracle Access Manager Authentication Bypass (CVSS 6.5)
Oracle Access Manager contains an authentication bypass vulnerability that allows attackers to gain unauthorized access to sensitive data without providing valid credentials. An attacker on a network can exploit this flaw through HTTP requests to read, modify, or delete data within the application. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0, and requires no special privileges or user interaction to exploit.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.5 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Weaknesses (CWE)
- CWE-287
- Affected products
- 2 configuration(s)
- Published / Modified
- 2026-06-17 / 2026-06-17
NVD description (verbatim)
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Access Manager accessible data as well as unauthorized read access to a subset of Oracle Access Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-35261 is an authentication engine vulnerability in Oracle Access Manager (Oracle Fusion Middleware) stemming from improper authentication controls (CWE-287). The vulnerability permits unauthenticated HTTP-based exploitation due to low attack complexity and no privilege requirements. The CVSS 3.1 score of 6.5 reflects combined confidentiality and integrity impacts: attackers can read a subset of accessible data and perform unauthorized create, update, and delete operations. The attack surface is the HTTP interface with no access vector restrictions, meaning any network-accessible instance is at risk.
Business impact
Access Manager is a critical identity and access control component in Oracle Fusion Middleware environments. Compromise enables attackers to manipulate user data, authentication records, and system configurations without detection or authorization. This can lead to privilege escalation, lateral movement within enterprise systems, compliance violations (especially in regulated industries), and reputational damage. Organizations relying on Access Manager for application and API authentication face direct threats to confidential data integrity and availability of downstream services.
Affected systems
Affected versions are Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0 within Oracle Fusion Middleware. Any deployment of these versions accessible via HTTP (including internal networks, DMZs, or cloud instances) is vulnerable. Organizations should audit their Access Manager inventory and network exposure immediately. Later or earlier versions may also be affected; consult Oracle's security advisory for a complete supported versions list.
Exploitability
This vulnerability is highly exploitable. It requires only network access to the HTTP interface, no authentication, no user interaction, and minimal attack complexity. The barrier to exploitation is low—a basic HTTP client and knowledge of the endpoint are sufficient. Given the ease of exploitation and the critical nature of Access Manager in authentication workflows, this should be treated as an active threat with high likelihood of exploitation attempts once public details emerge.
Remediation
Apply security patches from Oracle as documented in their official advisory. Verify patch version numbers against the vendor's guidance. If patching is delayed, implement network-level mitigations: restrict HTTP access to Access Manager to trusted hosts and networks only, deploy Web Application Firewalls (WAF) to monitor for suspicious authentication requests, and enable detailed logging and alerting on authentication failures and data modification attempts. Conduct post-remediation testing to confirm the vulnerability is eliminated.
Patch guidance
Consult Oracle's security advisory for CVE-2026-35261 to identify patched versions for each affected release line. Test patches in a non-production environment before production deployment. Prioritize patching for instances accessible from external networks or untrusted networks. Document patch application and maintain version records for compliance. Oracle typically releases patches through their Critical Patch Update (CPU) cycle; verify timing and compatibility with your environment's maintenance windows.
Detection guidance
Monitor for unusual HTTP requests to Access Manager endpoints lacking proper authentication headers or tokens. Alert on repeated failed authentication attempts or authentication bypass patterns. Log and analyze any successful requests that bypass expected authentication controls. Search historical logs for evidence of unauthorized data modification or deletion associated with unauthenticated sessions. Network-based detection: identify HTTP traffic to Access Manager ports from unexpected sources. Endpoint Detection and Response (EDR) tools should flag processes making unauthorized database queries through Access Manager.
Why prioritize this
Despite a CVSS score of 6.5 (Medium), this vulnerability warrants high priority because: (1) it impacts a foundational identity and access control component, (2) exploitation requires no authentication or complexity, (3) it enables both data theft and manipulation, and (4) Access Manager is often a trust boundary in enterprise architectures. A single successful compromise can cascade to compromise of downstream applications and data. Organizations should treat this as a priority patch regardless of CVSS rating.
Risk score, explained
The CVSS 3.1 score of 6.5 reflects a network-accessible vulnerability with no authentication or user interaction barriers (base factors: AV:N, AC:L, PR:N, UI:N). The score is constrained to Medium due to scope:unchanged and no availability impact. However, the practical risk is elevated because the vulnerability affects a critical security control (authentication engine), enabling both confidentiality and integrity breaches. Risk assessment should account for network exposure and the sensitivity of data protected by Access Manager, not CVSS score alone.
Frequently asked questions
What authentication controls are being bypassed?
The vulnerability exists in the Authentication Engine component. While the specific bypass mechanism is not disclosed in the summary, the CWE-287 classification (Improper Authentication) indicates the vulnerability allows attackers to circumvent normal authentication checks, enabling unauthenticated access to protected operations.
Are there any known public exploits for this vulnerability?
As of the publication date, this vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, suggesting active in-the-wild exploitation may not yet be documented. However, the ease of exploitation means proof-of-concept code could emerge quickly. Monitor threat intelligence sources and assume exploitation is likely.
Can this vulnerability be exploited from outside our network if Access Manager is internal-only?
If Access Manager is truly isolated to internal networks with no external connectivity, the network exposure is reduced but not eliminated. Internal attackers, compromised employees, or lateral movement from other breached systems can exploit it. Network segmentation and access controls should still be applied as defense-in-depth measures.
What data can an attacker actually access or modify?
The vulnerability permits unauthorized read access to a subset of Access Manager's accessible data and insert, update, and delete operations on other data. The exact scope of sensitive information exposed depends on what data is stored in your Access Manager instance (user credentials, policy configurations, audit logs, etc.). Conduct a data classification review specific to your deployment.
This analysis is provided for informational purposes and based on the published CVE description and CVSS vector. Organizations must verify all patch versions, affected software inventory, and remediation steps against Oracle's official security advisory. No exploit code or weaponized proof-of-concept is provided. The absence of KEV designation does not indicate the vulnerability is not actively exploited; organizations should assume exploitation risk and prioritize patching accordingly. Risk assessments should be tailored to your specific deployment, network architecture, and data sensitivity. Consult with Oracle support and internal security teams before applying patches to production systems. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-46827HIGHOracle E-Business Suite Payroll Remote Compromise – 8.8 CVSS
- CVE-2023-5502MEDIUMArista EOS 802.1x Authentication Bypass Vulnerability
- CVE-2026-10283MEDIUMBottelet DaybydayCRM Authentication Bypass in Settings Handler
- CVE-2026-10548MEDIUMImproper Authentication in NousResearch hermes-agent Credential Synchronization
- CVE-2026-40995MEDIUMSpring Web Services X509 Authentication Bypass Accounting Lifecycle Checks
- CVE-2026-45153MEDIUMNextcloud Android Files App PIN Bypass via Back Button
- CVE-2026-45283MEDIUMNextcloud File Lock Authorization Bypass
- CVE-2026-45289MEDIUMCloudburstMC Protocol Authentication Validation Bypass (MEDIUM)