Threats Tagged 'cve-2026-35261'
View all threats tagged with 'cve-2026-35261'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-35261'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-35261: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Access Manager accessible data as well as unauthorized read access to a subset of Oracle Access Manager accessible data. in Oracle Corporation Oracle Access ManagerCVE-2026-35261 0 CVE-2026-35261 is a vulnerability in Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 that allows an unauthenticated attacker with network access via HTTP to perform unauthorized read and write operations on accessible data. The vulnerability affects the Authentication Engine component of Oracle Fusion Middleware. It has a CVSS 3.1 base score of 6.5, indicating a medium severity level. Successful exploitation can lead to unauthorized update, insert, or delete access to some data, as well as unauthorized read access to a subset of data. Oracle has included this vulnerability in its June 2026 Critical Security Patch Update advisory, which contains patches for affected products. Customers are strongly advised to apply the security patches promptly to mitigate the risk. No specific patch version is explicitly stated for Oracle Access Manager in the provided advisory content, but the vendor strongly recommends applying the Critical Security Patch Update. Workarounds include blocking network protocols required by the attack or removing unnecessary privileges, though these may impact functionality. Join the discussion | CVE Database V5 | 06/16/2026, 19:26:54 UTC Added: 06/16/2026, 20:45:37 UTC |
Showing 1 to 1 of 1 result