CVE-2026-46852: Critical severity Oracle Oracle Enterprise Manager Base Platform vulnerability
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to Oracle Enterprise Manager Base Platform management interfaces (HTTPS) to trusted administrative IPs only. Enforce access via VPN or place the management interface behind a firewall, WAF, or network ACLs to block access from untrusted networks.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46852?
CVE-2026-46852 has a critical severity rating of 9.9.
What affected versions are associated with CVE-2026-46852?
CVE-2026-46852 affects Oracle Enterprise Manager Base Platform versions 13.5 and 24.1.
How do I fix CVE-2026-46852?
To remediate CVE-2026-46852, you should upgrade to a fixed version of Oracle Enterprise Manager Base Platform as recommended by Oracle.
What types of attacks are possible with CVE-2026-46852?
CVE-2026-46852 allows a low privileged attacker with network access via HTTPS to compromise the Oracle Enterprise Manager.
Is CVE-2026-46852 easily exploitable?
Yes, CVE-2026-46852 is considered easily exploitable due to its low privilege requirements.