Junglewise Threat Intelligence

CVE-2026-46852: Oracle Enterprise Manager privilege escalation in Metadata Plugin

CVE-2026-46852 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Oracle Enterprise Manager Base Platform. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle Enterprise Manager, a centralized management platform used to monitor and manage enterprise IT infrastructure. A user with low-level access can exploit this flaw over the network to take full control of the management platform. This could lead to a total loss of confidentiality and service availability, potentially impacting other connected systems across the organization.

Technical details

A vulnerability classified as Improper Privilege Management (CWE-269) exists in the Metadata Plugin component of Oracle Enterprise Manager Base Platform. The flaw is easily exploitable by a low-privileged attacker with network access via HTTPS. Because the vulnerability involves a scope change (CVSS S:C), a successful exploit allows an attacker to compromise not only the base platform but potentially impact additional integrated products. This can result in a complete takeover of the Oracle Enterprise Manager environment, affecting confidentiality, integrity, and availability. Affected versions include 13.5 and 24.1.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats