CVE-2026-70684: High severity Oracle Oracle Enterprise Manager Base Platform vulnerability
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Enterprise Manager Base Platform (Agent Next Gen)to a version that resolves this vulnerability.Fixed in 13.5 - Upgrade
Upgrade
Oracle Enterprise Manager Base Platform (Agent Next Gen)to a version that resolves this vulnerability.Fixed in 24.1
Event History
Frequently Asked Questions
Which deployments are affected?
Oracle Enterprise Manager Base Platform deployments using the Agent Next Gen component on supported versions 13.5 or 24.1 are affected.
Does exploitation require credentials or user interaction?
No. An unauthenticated attacker can exploit the issue over HTTP with network access, and no user interaction is required. The attack complexity is rated high.
What is the potential impact of a successful attack?
Successful exploitation can result in takeover of Oracle Enterprise Manager Base Platform, affecting confidentiality, integrity, and availability.