CVE-2026-60822: High severity Oracle Oracle Enterprise Manager for Systems Infrastructure vulnerability
Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Agent). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager for Systems Infrastructure executes to compromise Oracle Enterprise Manager for Systems Infrastructure. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager for Systems Infrastructure. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs a low-privileged account and the ability to log on to the infrastructure where Oracle Enterprise Manager for Systems Infrastructure runs. The attack is local and does not require user interaction.
Which deployments are known to be affected?
Affected supported versions are 13.5 and 24.1 of Oracle Enterprise Manager for Systems Infrastructure, specifically the Agent component.
What is the potential impact of successful exploitation?
A successful attack can result in takeover of Oracle Enterprise Manager for Systems Infrastructure, with high impacts to confidentiality, integrity, and availability.