CVE-2026-35313: Critical severity Oracle Oracle Access Manager vulnerability
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable or restrict HTTP access to the Oracle Access Manager Authentication Engine for affected installations (12.2.1.4.0 and 14.1.2.1.0). If disabling HTTP entirely is not feasible, restrict it to trusted management networks only.
Oracle Access Manager (Authentication Engine) HTTP access = disabled or restricted - Compensating control
Apply network-level controls (firewall rules, ACLs, WAF) to block or restrict HTTP access to Oracle Access Manager Authentication Engine from untrusted networks and the public Internet; allow only trusted IP ranges and management hosts.
- Operational
Perform incident response for any potentially affected Oracle Access Manager instances: investigate for signs of compromise (takeover indicators), assume compromise if evidence is found, rotate credentials and keys used by the service, and restore from known-good backups or rebuild affected hosts as needed.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35313?
CVE-2026-35313 has a critical severity score of 9.9.
How do I fix CVE-2026-35313?
The recommended fix for CVE-2026-35313 is to upgrade to a version of Oracle Access Manager that is not affected by this vulnerability.
What components of Oracle Fusion Middleware are impacted by CVE-2026-35313?
CVE-2026-35313 specifically affects the Authentication Engine component of Oracle Access Manager.
Who can exploit the CVE-2026-35313 vulnerability?
CVE-2026-35313 can be exploited by a low privileged attacker with network access via HTTP.
What versions of Oracle Access Manager are affected by CVE-2026-35313?
The affected versions of Oracle Access Manager are 12.2.1.4.0 and 14.1.2.1.0.