CVE-2026-61300: High severity Oracle Oracle Enterprise Manager Base Platform vulnerability
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base Platform executes to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs a low-privileged account and logon access to the infrastructure where Oracle Enterprise Manager Base Platform is running. The attack is local and does not require user interaction.
Which deployments are known to be affected?
Affected supported versions are Oracle Enterprise Manager Base Platform 13.5 and 24.1, specifically the Agent Next Gen component.
What is the potential impact of successful exploitation?
Successful exploitation can result in takeover of Oracle Enterprise Manager Base Platform, with high confidentiality, integrity, and availability impact.