Back to Blog

Emerging Threat: (CVE-2026-60358) Oracle Access Manager Takeover via Authentication Engine

What is CVE-2026-60358?

CVE-2026-60358 is a vulnerability in the Authentication Engine component of Oracle Access Manager, the single sign-on product in the Oracle Fusion Middleware stack. Oracle disclosed it on July 21, 2026 as part of the July 2026 Critical Patch Update.

The vulnerability carries a CVSS v3.1 base score of 10.0 (Critical). That score was assigned by Oracle as the CNA. NVD has received the record but had not published its own assessment at the time of writing.

Exploitation is pre-authentication. Oracle describes the flaw as easily exploitable by an unauthenticated attacker with network access over HTTP, with no user interaction and no credentials required. A successful attack results in takeover of Oracle Access Manager.

The score reaches 10.0 because of scope change. Oracle states that attacks may significantly impact products beyond Access Manager itself, which follows directly from what the product does. Access Manager issues and validates the sessions that other applications trust. An attacker who controls the authentication broker controls who those applications believe they are talking to, which means the blast radius is the set of systems sitting behind the login, not the login server alone. Oracle does not publish root cause details, and at the time of writing there was no public exploit code and no confirmed reporting of exploitation in the wild.

What assets are affected by CVE-2026-60358?

The advisory names Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0 as the affected supported versions. Oracle tests only releases covered by Premier or Extended Support, and states that earlier releases are likely affected as well without receiving patches. Organizations running unsupported Access Manager versions should assume they are exposed.

In practice, an affected asset is a web-facing login endpoint. Access Manager runs on Oracle WebLogic Server and typically sits at the front of a portal estate, handling authentication for supplier portals, dealer and partner systems, customer self-service applications, and ERP front ends.

These assets are internet-facing by design rather than by accident. The whole purpose of the deployment is to authenticate users who are not on the corporate network, so the service has to be reachable from the internet to function. That also makes it difficult to take offline for emergency maintenance, because pulling the authentication broker down takes every application behind it down at the same time.

The Authentication Engine has drawn repeated attention this year. Oracle patched separate flaws in the same component in its June 2026 Critical Security Patch Update, affecting the same two supported versions. Access Manager also has exploitation history: CVE-2021-35587, a pre-authentication remote code execution flaw in the product’s OpenSSO Agent component, was added to the CISA Known Exploited Vulnerabilities catalog in November 2022 after confirmed exploitation, and was later reported as the entry point in a cloud tenant breach.

What does our data show about exposure patterns?

The Access Manager assets visible in our data are web applications rather than bare hosts, and they follow a recognizable pattern: supplier and procurement portals, dealer systems, and dedicated SSO subdomains sitting in front of ERP environments. Exposure is concentrated in energy and automotive, with a smaller presence in banking. What those sectors share is a large population of authenticated users who are not employees. Suppliers, contractors, and dealers need access to internal business systems without holding a corporate identity, and Access Manager is the component that decides whether they get it. That matters for triage, because an Access Manager instance serving a partner ecosystem has a wider set of downstream applications behind it than one serving an internal user base.

Are fixes available?

Yes. Oracle addressed CVE-2026-60358 in the July 2026 Critical Patch Update, released on July 21, 2026. The fix is delivered through the Fusion Middleware patch set, and Oracle publishes the applicable patch availability document for Fusion Middleware on My Oracle Support.

Two caveats matter. First, the July 2026 Critical Patch Update contains 1,449 new security patches, the largest Oracle has shipped in a single quarterly release, and Fusion Middleware carries a large share of them. Teams working through the update should not assume that a generic Fusion Middleware patch cycle covers this specific issue without checking. Second, patches exist only for supported versions, so organizations on older Access Manager releases will need an upgrade rather than a patch.

Oracle’s interim guidance is to block the network protocols an attack requires where patching cannot happen immediately, while noting that this can break application functionality and does not correct the underlying flaw. For Access Manager, blocking HTTP access generally means taking the SSO service offline for external users, so treat it as a containment measure of last resort rather than a workaround. Defenders should verify patch applicability directly with Oracle for their specific deployment and version rather than assuming coverage.

Until patching is confirmed, defenders should:

  • Inventory every Oracle Access Manager instance reachable from the public internet
  • Restrict HTTP access to Access Manager endpoints to known networks
  • Review Access Manager logs for sessions issued without a matching authentication event
  • Audit administrative accounts and policy changes for unauthorized modifications
  • Rotate service account credentials and federation trust secrets after remediation
  • Treat applications that trust Access Manager sessions as in scope

How can CyCognito help your organization?

CyCognito published an Emerging Threat Advisory for CVE-2026-60358 in the CyCognito platform and is actively researching enhanced detection capabilities for this vulnerability.

To learn how CyCognito can help your organization reduce external exposure and manage emerging threats more effectively, contact us to request a demo.


Request a free scan

See Exactly What Attackers See

Get a free scan of your attack surface and gain valuable insight into your organization's risk posture by allowing CyCognito to discover, contextualize, and test externally .

Request a Scan
Top Attack Paths