CVE-2026-35261: Medium severity Oracle Oracle Access Manager vulnerability
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Access Manager accessible data as well as unauthorized read access to a subset of Oracle Access Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to Oracle Access Manager's HTTP interface to trusted IPs or internal network segments using firewall rules, ACLs, or a WAF. Block or otherwise prevent unauthenticated HTTP access from untrusted/public networks until a vendor fix is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35261?
CVE-2026-35261 is classified with a medium severity score of 6.5.
How do I fix CVE-2026-35261?
To mitigate CVE-2026-35261, you should update your Oracle Access Manager to the latest version that addresses this vulnerability.
What products are impacted by CVE-2026-35261?
CVE-2026-35261 affects the Oracle Access Manager component of Oracle Fusion Middleware, specifically versions 12.2.1.4.0 and 14.1.2.1.0.
Can CVE-2026-35261 be exploited remotely?
Yes, CVE-2026-35261 can be exploited by an unauthenticated attacker with network access via HTTP.
What type of vulnerability is CVE-2026-35261?
CVE-2026-35261 is categorized as a vulnerability in the Authentication Engine of Oracle Access Manager.