HIGH 7.2

CVE-2026-46867: Oracle Enterprise Manager Base Platform Remote Takeover via Extensibility Framework

Oracle Enterprise Manager Base Platform contains a vulnerability in its Extensibility Framework that allows high-privileged attackers with network access to take over the system. The flaw affects versions 13.5 and 24.1, and exploitation requires HTTPS connectivity but does not need user interaction. A successful attack grants an attacker complete control over the Enterprise Manager platform, including ability to read, modify, or destroy data and disable services.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.2 HIGH · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-269
Affected products
2 configuration(s)
Published / Modified
2026-06-17 / 2026-06-18

NVD description (verbatim)

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Extensibility Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-46867 is a privilege-abuse vulnerability (CWE-269) in Oracle Enterprise Manager Base Platform's Extensibility Framework. The CVSS 3.1 vector (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) indicates that while the attack vector is network-based with low complexity, exploitation requires high-level privileges—meaning an authenticated administrator or similarly privileged account is needed to trigger the flaw. The vulnerability does not require user interaction and impacts confidentiality, integrity, and availability equally. Affected versions are 13.5 and 24.1; the attack surface is the HTTPS interface.

Business impact

Control of Enterprise Manager is equivalent to control of the entire Oracle infrastructure it manages. An attacker exploiting this vulnerability could alter monitoring policies, disable alerts, modify managed system configurations, exfiltrate sensitive environment data, or introduce persistent backdoors across the monitored estate. For organizations relying on Enterprise Manager for multi-system orchestration and compliance reporting, compromise could undermine audit trails and operational visibility across critical applications.

Affected systems

Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are affected. Systems running these specific versions with network-accessible HTTPS interfaces are at risk. Organizations should audit their Enterprise Manager deployments to identify which versions are in production and prioritize those on affected releases.

Exploitability

Exploitation is rated 'easily exploitable' by Oracle, but this reflects the low technical barrier once a high-privileged account is available. An attacker must already possess administrative credentials or equivalent network access to a privileged user session. The flaw does not grant initial access to unprivileged users; it amplifies the impact of a compromised admin account. However, given the high-privilege requirement, the actual exploitation window depends on the organization's identity governance and session management practices.

Remediation

Oracle has issued patches for affected versions; contact Oracle directly or consult the official security advisory for patch version numbers, release dates, and applicability to your specific Enterprise Manager deployment. Testing patches in a non-production environment is essential before applying to production instances, as Enterprise Manager changes can affect downstream monitoring and alerting. Consider temporarily restricting HTTPS access to Enterprise Manager consoles to trusted networks while patches are prepared and deployed.

Patch guidance

Obtain the latest security patches from Oracle's Critical Patch Update (CPU) releases or directly from Oracle Support. Verify patch applicability to your exact Enterprise Manager version (13.5 or 24.1). Plan patching during a maintenance window to avoid disruption to monitoring. Test thoroughly in a staging environment that mirrors your production configuration before applying to live systems. Document the patching timeline and validate that monitoring and alerting resume normally after the patch is applied.

Detection guidance

Monitor HTTPS access logs to Enterprise Manager for unusual administrative activity, such as privilege-escalation attempts, Extensibility Framework modifications, or policy changes from unexpected accounts. Review audit logs within Enterprise Manager for changes to plug-in configurations, user permissions, or system settings made by high-privileged accounts. Look for network connections from privileged user sessions to Enterprise Manager that are not consistent with normal administrative workflows. Enable detailed logging for the Extensibility Framework if available.

Why prioritize this

Although the CVSS score is 7.2 (HIGH), the requirement for high privileges reduces the likelihood of external attacks but elevates the risk of insider threats and post-compromise lateral movement. Prioritize patching if you have a history of compromised admin accounts, if Enterprise Manager is internet-facing, or if insider threats are a concern in your organization. Systems in air-gapped or highly restricted networks present lower immediate risk but should still be patched per Oracle's guidance.

Risk score, explained

The CVSS 3.1 score of 7.2 reflects the high impact potential (complete confidentiality, integrity, and availability compromise) balanced against the high-privilege prerequisite. The 'easily exploitable' designation refers to the low complexity once privileges are obtained, not the ease of gaining those privileges. The score does not account for the business criticality of Enterprise Manager; organizations should raise their internal priority if Enterprise Manager underpins mission-critical monitoring or compliance reporting.

Frequently asked questions

Do I need to patch immediately if my Enterprise Manager is behind a firewall?

Firewall placement reduces exposure but does not eliminate risk. Compromised internal accounts, lateral movement, or VPN access by attackers could still reach Enterprise Manager. Prioritize patching based on your organization's threat model and the criticality of Enterprise Manager to your operations, but do not rely solely on network isolation.

What happens if an attacker exploits this vulnerability?

An attacker gains full administrative control of Enterprise Manager, including the ability to read and modify monitored system configurations, alter alerting rules, inject backdoors, exfiltrate data, or disable monitoring entirely. This is equivalent to compromising all systems that Enterprise Manager manages if the attacker uses their access to propagate further attacks.

Are older versions of Enterprise Manager affected?

Only versions 13.5 and 24.1 are listed as affected by Oracle. If you run a different version, verify with Oracle's official advisory to confirm your version's status. Oracle typically maintains support lifecycles for major versions; check if your version is still receiving security updates.

How long will Enterprise Manager be unavailable during patching?

Downtime depends on your Enterprise Manager architecture, patch application method, and whether you have high-availability or redundancy configured. Plan for at least a few hours of testing and patching in a staging environment before applying to production. Coordinate with teams that depend on Enterprise Manager monitoring to schedule the patch window.

This analysis is based on Oracle's official CVE disclosure and CVSS metrics as of the publication date. Patch availability, version support timelines, and remediation steps are subject to change; verify all patch information directly with Oracle or your organization's vendor resources before implementing any remediation. This summary is for informational purposes and does not constitute security advice. Organizations must assess their own risk tolerance, compliance requirements, and operational constraints when prioritizing patches. No exploit code or proof-of-concept is provided; the vulnerability description is for defensive and awareness purposes only. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).