CVE-2026-35314
Awaiting Analysis Awaiting Analysis - Queue
Unauthenticated Access in Oracle Access Manager

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Oracle

Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Web Server Plugin). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Access Manager accessible data as well as unauthorized read access to a subset of Oracle Access Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Access Manager. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
oracle access_manager 12.2.1.4.0
oracle access_manager 14.1.2.1.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Compliance Impact

This vulnerability allows an unauthenticated attacker to gain unauthorized read and write access to Oracle Access Manager data, as well as cause partial denial of service. Such unauthorized access and potential data manipulation can lead to violations of data protection and privacy requirements found in standards like GDPR and HIPAA, which mandate strict controls over data confidentiality, integrity, and availability.

Therefore, exploitation of this vulnerability could result in non-compliance with these regulations due to unauthorized data exposure and modification.

Executive Summary

This vulnerability exists in the Oracle Access Manager product of Oracle Fusion Middleware, specifically in the Web Server Plugin component. It affects supported versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability is easily exploitable by an unauthenticated attacker with network access via HTTP.

Successful exploitation can allow the attacker to perform unauthorized updates, inserts, or deletions of some data accessible by Oracle Access Manager. Additionally, the attacker can gain unauthorized read access to a subset of this data and cause a partial denial of service (partial DOS) on Oracle Access Manager.

Impact Analysis

The impact of this vulnerability includes unauthorized modification (update, insert, delete) and unauthorized reading of some data managed by Oracle Access Manager. This can lead to data integrity and confidentiality breaches.

Furthermore, the vulnerability can cause a partial denial of service, affecting the availability of Oracle Access Manager services.

Overall, the vulnerability affects confidentiality, integrity, and availability, with a CVSS 3.1 base score of 7.3, indicating a high severity risk.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-35314. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart