CVE-2026-46868: High severity Oracle Enterprise Manager Base Platform vulnerability
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Extensibility Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to the Oracle Enterprise Manager Base Platform HTTPS endpoint to only trusted administrator IPs/networks using firewall rules or ACLs. Block or deny HTTPS access from untrusted networks (including the public Internet).
- Compensating control
Move or isolate the Oracle Enterprise Manager Base Platform onto a dedicated management network/VLAN and permit access to it only from authorized management hosts and jump boxes; deny direct access from general-purpose or user networks.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46868?
The severity of CVE-2026-46868 is rated high with a score of 7.2.
How do I fix CVE-2026-46868?
To fix CVE-2026-46868, you should update to a patched version of the Oracle Enterprise Manager Base Platform.
What versions are affected by CVE-2026-46868?
CVE-2026-46868 affects Oracle Enterprise Manager Base Platform versions 13.5 and 24.1.
Who is primarily affected by CVE-2026-46868?
CVE-2026-46868 primarily affects organizations using Oracle Enterprise Manager Base Platform with network access.
What type of attack does CVE-2026-46868 allow?
CVE-2026-46868 allows a high privileged attacker with network access via HTTPS to compromise the system.