← Back to browse · API

CVE-2026-60358

Severity
CRITICAL
CVSS
10.0
EPSS
0.00473
Risk score
40.17
CISA KEV
No
PoC
No
Published
2026-07-21
Modified
2026-07-28
First seen
2026-08-05
Aliases
EUVD-2026-46772, GHSA-55XR-Q9C4-GJ9C
Products
Oracle:Oracle Access Manager 12.2.1.4.0, Oracle:Oracle Access Manager 14.1.2.1.0, oracle:access_manager
Sources
nvd CVE-2026-60358
euvd EUVD-2026-46772

Description

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

References