Junglewise Threat Intelligence

CVE-2026-46832: Oracle Enterprise Manager Base Platform compromise in Discovery Framework

CVE-2026-46832 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Oracle Enterprise Manager Base Platform. Vendors: Oracle.

Executive brief

A critical vulnerability has been identified in Oracle Enterprise Manager, a centralized management platform used to monitor and manage IT infrastructure. An attacker with low-level access to the network can exploit this flaw to take full control of the management platform. Because this tool manages other systems, a successful attack could allow the intruder to compromise additional connected products and services across the organization.

Technical details

A vulnerability exists in the Discovery Framework component of Oracle Enterprise Manager Base Platform (versions 13.5 and 24.1). The flaw is classified as easily exploitable and allows a low-privileged attacker with network access via HTTPS to compromise the platform. The vulnerability includes a 'scope change' (CVSS S:C), meaning a successful exploit can extend beyond the Enterprise Manager itself to impact other products managed by the platform. Successful exploitation results in a complete takeover of the Oracle Enterprise Manager Base Platform, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle June 2026 Security Alert for patching information.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats