CVE-2026-61284: High severity Oracle Enterprise Manager Base Platform vulnerability
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Config Console). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs network access to the affected Application Config Console over HTTP and a low-privileged account. No user interaction is required.
Which deployments are known to be affected?
The affected component is Application Config Console in Oracle Enterprise Manager Base Platform. Supported affected versions are 13.5 and 24.1.
What is the potential impact of a successful attack?
A successful attack can result in takeover of Oracle Enterprise Manager Base Platform, with high impacts to confidentiality, integrity, and availability.