CVE-2026-46864: High severity Oracle Enterprise Manager Base Platform vulnerability
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via SSH to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Oracle Enterprise Manager (Agent Next Gen)from your environment.Uninstall or remove the Agent Next Gen component if it is not required in your environment.
- Configuration
Disable SSH access to the Agent Next Gen component where possible. If SSH is required, restrict SSH to only trusted management hosts (limit listening interfaces, use allowlists) and enforce strong authentication.
Oracle Enterprise Manager (Agent Next Gen) SSH access = disabled or restricted to trusted hosts - Compensating control
Restrict network access to Oracle Enterprise Manager Base Platform management interfaces: block or allowlist SSH at perimeter firewalls/ACLs, place the management system on an isolated management network/VLAN, and deny SSH from untrusted networks.
- Operational
Monitor logs and network traffic for suspicious activity against Oracle Enterprise Manager and Agent Next Gen. If compromise is suspected, perform incident response actions including credential and key rotation, system restoration from known-good backups, and forensic investigation.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46864?
The severity of CVE-2026-46864 is high with a CVSS score of 8.8.
How can I fix CVE-2026-46864?
To fix CVE-2026-46864, users should update to a patched version of Oracle Enterprise Manager Base Platform as instructed in Oracle's security advisory.
What software is affected by CVE-2026-46864?
CVE-2026-46864 affects the Oracle Enterprise Manager Base Platform, specifically versions 13.5 and 24.1.
What type of access is required to exploit CVE-2026-46864?
CVE-2026-46864 can be exploited by a low privileged attacker with network access via SSH.
What potential impact does CVE-2026-46864 have on affected systems?
The potential impact of CVE-2026-46864 includes high confidentiality, integrity, and availability risks, allowing attackers to compromise the Oracle Enterprise Manager.