HIGH 7.2

CVE-2026-46868: Oracle Enterprise Manager Base Platform Privilege Escalation Vulnerability

A vulnerability exists in Oracle Enterprise Manager Base Platform that allows an authenticated administrator to gain complete control over the platform. The flaw is in the Extensibility Framework component and requires the attacker to already have high-privilege credentials and network access via HTTPS. Successful exploitation results in full compromise of the Enterprise Manager instance, affecting confidentiality, integrity, and availability. Versions 13.5 and 24.1 are affected.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.2 HIGH · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-284
Affected products
2 configuration(s)
Published / Modified
2026-06-17 / 2026-06-18

NVD description (verbatim)

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Extensibility Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-46868 is an improper access control vulnerability (CWE-284) in the Extensibility Framework of Oracle Enterprise Manager Base Platform. The attack vector is network-based over HTTPS with low attack complexity, but requires high privilege account credentials for initial access. The vulnerability permits an authenticated high-privileged user to execute actions that should be restricted, leading to complete takeover of the Enterprise Manager Base Platform. The CVSS 3.1 score of 7.2 reflects the high-impact nature of successful exploitation across all security objectives.

Business impact

Enterprise Manager Base Platform provides centralized management and monitoring of Oracle infrastructure. Compromise of this system via this vulnerability could allow an attacker with admin credentials to alter monitoring policies, disable security controls, manipulate audit logs, inject malicious extensions, or disrupt critical operational visibility. The impact extends to any systems managed by the affected Enterprise Manager instance. For organizations relying on Enterprise Manager for compliance reporting and security monitoring, unauthorized access could undermine audit trails and create significant governance risk.

Affected systems

Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are confirmed as vulnerable. Organizations running these versions should inventory their Enterprise Manager deployments. The vulnerability requires network connectivity to the Enterprise Manager HTTPS port, so systems behind restrictive network policies may have reduced exposure, but internal access should not be assumed safe.

Exploitability

While the CVSS vector indicates 'easily exploitable' in terms of attack complexity, exploitation requires an attacker to already possess high-privileged account credentials. This raises the practical barrier to exploitation. The threat is primarily from insider threats or compromise of administrative accounts through credential theft or phishing. External adversaries would need to first compromise a privileged account before leveraging this flaw. The lack of KEV (Known Exploited Vulnerability) designation as of publication indicates this has not yet been observed in active campaigns.

Remediation

Verify the availability of security patches from Oracle for Enterprise Manager Base Platform versions 13.5 and 24.1 against the vendor advisory. Apply patches promptly to mitigate the access control flaw. As an interim control, restrict network access to Enterprise Manager HTTPS interfaces to only trusted administrative networks and audit high-privilege account activities for suspicious behavior.

Patch guidance

Consult Oracle's security advisory for CVE-2026-46868 to identify patched versions for both 13.5 and 24.1 branches. Test patches in a non-production Enterprise Manager environment to validate compatibility with existing extensions and customizations before production deployment. Given that Enterprise Manager often manages critical infrastructure, coordinate patching with change management processes and schedule during maintenance windows.

Detection guidance

Monitor Enterprise Manager for unusual administrative activities, particularly actions taken by high-privilege accounts that trigger changes to the Extensibility Framework or extension deployments. Review audit logs for unexpected modifications to monitoring policies, credential management changes, or disablement of security controls. Network-level monitoring for suspicious HTTPS access patterns to Enterprise Manager ports, combined with correlation of account activity logs, can help identify exploitation attempts. Log aggregation and SIEM integration of Enterprise Manager audit data is recommended.

Why prioritize this

While the CVSS score of 7.2 is elevated, the practical risk is moderated by the requirement for high-privilege credentials. However, this vulnerability should still be prioritized because: (1) it affects widely-deployed versions of a critical infrastructure management tool; (2) successful exploitation grants complete platform control; (3) affected administrators may not immediately detect unauthorized actions; and (4) the Extensibility Framework's role in managing plugins and integrations means compromise could cascade to dependent systems. Organizations with strong access controls limiting high-privilege accounts have lower immediate risk than those with broadly distributed admin credentials.

Risk score, explained

The CVSS 3.1 base score of 7.2 (HIGH severity) reflects a vulnerability with network-based attack vector, low complexity once credentials are obtained, and severe impact across confidentiality, integrity, and availability. The moderating factor is the requirement for high privilege level (PR:H), which limits the population of attackers who can exploit this flaw. Organizations should not discount this risk; instead, layer it with assessment of their own administrative credential hygiene and network segmentation.

Frequently asked questions

Does this vulnerability affect my Enterprise Manager deployment if I'm not on versions 13.5 or 24.1?

No, only versions 13.5 and 24.1 are listed as affected. If you are running a different version, you are not vulnerable to this specific flaw. However, verify your exact version number in Enterprise Manager's system settings to confirm.

Can this vulnerability be exploited by someone without administrator credentials?

No. The vulnerability explicitly requires high-privilege account access and network connectivity via HTTPS. An external attacker would first need to compromise an administrative account through other means (phishing, credential theft, etc.) before attempting to exploit this flaw.

Should I take Enterprise Manager offline while waiting for a patch?

Only if your risk tolerance is very low. Since exploitation requires high-privilege credentials, the primary mitigation is restricting administrative access to trusted users and networks, and monitoring for anomalous activities. Offlining Enterprise Manager impacts operational visibility across your infrastructure, so evaluate the trade-off with your internal controls and network segmentation.

Is there any public exploit code or active exploitation?

As of the CVE publication date, this vulnerability has not been added to CISA's Known Exploited Vulnerabilities (KEV) list, indicating no documented active exploitation campaigns. However, always verify current threat intelligence feeds for the latest information.

This analysis is provided for informational purposes based on the CVE record and Oracle's published vulnerability statement. For definitive patch availability, version compatibility, and remediation guidance, consult Oracle's official security advisory for CVE-2026-46868. Verify all patch versions and deployment steps against the vendor's documentation before implementation. This vulnerability has not been designated as a Known Exploited Vulnerability as of the publication date, but threat landscape may change; review current threat intelligence sources. SEC.co makes no warranty regarding the completeness or accuracy of this analysis and recommends organizations apply their own risk assessment based on their specific environment, controls, and business context. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).