CVE-2026-46853: XSS
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Oracle Enterprise Manager (Metadata Plugin)from your environment.If the Metadata Plugin is not required, disable or uninstall the Metadata Plugin to remove the affected component.
- Compensating control
Restrict network access to Oracle Enterprise Manager's HTTP interface to trusted management IPs only (block inbound HTTP from untrusted networks) and isolate the service on a management network/VLAN.
- Compensating control
Deploy a web application firewall (WAF) or HTTP filtering in front of Oracle Enterprise Manager to detect and block malicious HTTP requests targeting the Metadata Plugin.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46853?
The severity of CVE-2026-46853 is rated critical with a score of 9.6.
How do I fix CVE-2026-46853?
To fix CVE-2026-46853, you should apply the latest security patches provided by Oracle for versions 13.5 and 24.1.
Who is affected by CVE-2026-46853?
CVE-2026-46853 affects users of the Oracle Enterprise Manager Base Platform running versions 13.5 and 24.1.
What type of vulnerability is CVE-2026-46853?
CVE-2026-46853 is classified as an XSS (Cross-Site Scripting) vulnerability.
What are the potential impacts of CVE-2026-46853?
The potential impacts of CVE-2026-46853 include unauthorized access and compromise of the Oracle Enterprise Manager through unauthenticated network access.