Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-35313 -- CVSS 9.9 Vulnerability Briefing

CVE-2026-35313 | CVSS 9.9 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-35313 is a critical vulnerability in Oracle Access Manager, a component of Oracle Fusion Middleware, specifically affecting the Authentication Engine in versions 12.2.1.4.0 and 14.1.2.1.0.

Technical Detail

The flaw resides in the Authentication Engine of Oracle Access Manager and is described as easily exploitable, indicating low attack complexity with no special preconditions required for an attacker to trigger it. Based on the CVSS score of 9.9 and the affected component, the vulnerability likely enables an unauthenticated or low-privileged network-based attacker to achieve unauthorized access, authentication bypass, or remote code execution against the identity and access management layer. Successful exploitation could grant an attacker control over authentication workflows, potentially compromising all systems and users relying on Oracle Access Manager for identity brokering.

Exploitation Status

No known exploit has been publicly documented or observed in the wild as of June 24, 2026. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Despite the absence of confirmed exploitation, the critical severity and low attack complexity make this a high-priority target for threat actors monitoring Oracle advisory disclosures.

Who Is Targeting This

No confirmed threat actor attribution has been established for this CVE. Reported (research-inferred, medium confidence): DEEPPANDA, CARBANAK, LOTUSBLOSSOM, AXIOM, and MOONSTONESLEET have been associated with this vulnerability through research-level inference. No origin country or specific motivation has been confirmed for any of these actors in relation to this CVE. These associations should be treated as preliminary and not as verified operational intelligence.

What To Do

Apply Oracle's official patch for Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 immediately, prioritizing internet-facing or externally accessible deployments. Organizations should consult Oracle's Critical Patch Update advisory for the specific patch identifier and apply it within an emergency change window given the 9.9 CVSS score. Until patching is complete, restrict network access to the Oracle Access Manager Authentication Engine to trusted internal networks and enforce additional authentication controls at the perimeter. Monitor authentication logs for anomalous access patterns, unexpected session creation, or authentication bypass indicators. If no patch is yet available for a specific sub-version, contact Oracle support for interim guidance and consider isolating the affected instance from untrusted network segments.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →