CVE-2026-46995: High severity Oracle Enterprise Manager Base Platform vulnerability
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to Oracle Enterprise Manager Base Platform (Metadata Plugin) over HTTPS so low-privileged attackers cannot reach the affected service.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46995?
CVE-2026-46995 has a high severity rating of 8.8.
How do I fix CVE-2026-46995?
To mitigate CVE-2026-46995, update your Oracle Enterprise Manager Base Platform to the latest patched version.
What versions are affected by CVE-2026-46995?
CVE-2026-46995 affects Oracle Enterprise Manager Base Platform version 13.5 and 24.1.
What type of access is required to exploit CVE-2026-46995?
A low privileged attacker with network access via HTTPS can exploit CVE-2026-46995.
What components are involved in CVE-2026-46995?
CVE-2026-46995 involves a vulnerability in the Metadata Plugin component of Oracle Enterprise Manager.