CVE-2026-70905 – Oracle Access Manager

CVSS 9.8 CRITICAL Critical - Same Day Deployment

“An unauthenticated SAML attack can fully compromise confidentiality, integrity, and availability.”

Oracle addresses a Critical vulnerability in the Agent Infrastructure component of Oracle Access Manager. CVE-2026-70905 is remotely exploitable over SAML without authentication and can result in high impact to confidentiality, integrity, and availability. The CVSS score is 9.8, which is Critical severity.

Affected versions include Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0. The issue is addressed in Oracle’s August 2026 Critical Security Patch Update.

Key Details

Affected Product
Oracle Access Manager
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-287
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.