CVE-2026-70905 – Oracle Access Manager
CVSS 9.8
CRITICAL
Critical - Same Day Deployment
“An unauthenticated SAML attack can fully compromise confidentiality, integrity, and availability.”
Oracle addresses a Critical vulnerability in the Agent Infrastructure component of Oracle Access Manager. CVE-2026-70905 is remotely exploitable over SAML without authentication and can result in high impact to confidentiality, integrity, and availability. The CVSS score is 9.8, which is Critical severity.
Affected versions include Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0. The issue is addressed in Oracle’s August 2026 Critical Security Patch Update.
Key Details
- Affected Product
- Oracle Access Manager
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-287
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.