CVE-2026-35261
Awaiting Analysis Awaiting Analysis - Queue
Authentication Bypass in Oracle Access Manager

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Oracle

Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Access Manager accessible data as well as unauthorized read access to a subset of Oracle Access Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
oracle access_manager 12.2.1.4.0
oracle access_manager 14.1.2.1.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the Oracle Access Manager product, specifically in the Authentication Engine component of Oracle Fusion Middleware. It affects supported versions 12.2.1.4.0 and 14.1.2.1.0.

An unauthenticated attacker with network access via HTTP can exploit this vulnerability easily. Successful exploitation allows the attacker to perform unauthorized updates, inserts, or deletions on some data accessible by Oracle Access Manager, as well as unauthorized read access to a subset of that data.

Impact Analysis

The impact of this vulnerability includes unauthorized modification and disclosure of data within Oracle Access Manager. An attacker could alter or delete data they should not have access to, or read sensitive information without authorization.

This can lead to compromised data integrity and confidentiality, potentially affecting the security and trustworthiness of systems relying on Oracle Access Manager for authentication and access control.

Compliance Impact

This vulnerability allows an unauthenticated attacker with network access to compromise Oracle Access Manager, resulting in unauthorized read and write access to some accessible data. Such unauthorized access and modification of data can potentially lead to violations of data protection standards and regulations like GDPR and HIPAA, which require strict controls over data confidentiality and integrity.

Because the vulnerability impacts confidentiality and integrity of data, organizations using affected versions of Oracle Access Manager may face increased risk of non-compliance with these regulations if exploited.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-35261. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart