CVE-2026-60326
CVE-2026-60326 is a critical vulnerability in Oracle Access Manager's Authentication Engine affecting versions 12.2.1.4.0 and 14.1.2.1.0. An unauthenticated attacker with network access via HTTP can exploit it to read, modify, or delete critical data accessible to the product. The flaw impacts confidentiality and integrity, earning a CVSS 3.1 base score of 9.1.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Oracle Access Manager (Oracle Fusion Middleware) versions 12.2.1.4.0 and 14.1.2.1.0.
Real-world impact
Attackers can gain unauthorized access to sensitive data and alter or delete it without needing any credentials, potentially leading to data breaches or loss of integrity.
Why this severity
The CVSS score of 9.1 reflects a network‑reachable, low‑complexity attack that requires no privileges or user interaction and results in high confidentiality and integrity impacts.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources.
Timeline
- Jul 21, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 28, 2026 · 5d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- oracle.com/security-alerts/cpujul2026.…vendor advisory