CVE-2026-46858: Critical severity Oracle Oracle Enterprise Manager APM - Application Performance Management vulnerability
Vulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM Diagnostics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise APM - Application Performance Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all APM - Application Performance Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of APM - Application Performance Management. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable or remove public/unnecessary HTTP access to the APM interface. If HTTP access is required, restrict it to a management network or a whitelist of trusted IP addresses and require authentication.
APM - Application Performance Management (Oracle Enterprise Manager) HTTP access/exposure = disabled or restricted to trusted IPs/networks - Compensating control
Place network controls (firewall rules, network ACLs) to block or limit HTTP access to the APM service to only trusted IPs or management networks. Consider deploying a WAF in front of the APM HTTP interface to filter malicious requests.
- Operational
Monitor logs and network traffic for signs of exploitation (unauthorized creation, deletion, modification, crashes). If compromise is suspected, isolate affected hosts, restore impacted data from known-good backups, and rotate any credentials or keys that may have been exposed or could be used to access APM.
- Operational
Track Oracle security advisories for this issue and apply vendor-supplied patches or updates as soon as they are released for APM / Oracle Enterprise Manager.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46858?
The severity of CVE-2026-46858 is critical, with a CVSS score of 9.1.
How do I fix CVE-2026-46858?
To fix CVE-2026-46858, users should upgrade to the latest supported versions of Oracle Application Performance Management.
Can CVE-2026-46858 be exploited remotely?
Yes, CVE-2026-46858 can be exploited remotely by an unauthenticated attacker with network access via HTTP.
Which versions of Oracle Enterprise Manager are affected by CVE-2026-46858?
The affected versions of Oracle Enterprise Manager related to CVE-2026-46858 are 13.5 and 24.1.
What impact does CVE-2026-46858 have on system integrity?
CVE-2026-46858 can lead to a compromise of system integrity, with potential unauthorized changes to system behavior.