Junglewise Threat Intelligence

CVE-2026-46853: Oracle Enterprise Manager Base Platform XSS in Metadata Plugin

CVE-2026-46853 · Severity: critical · CVSS 9.6 · Published 2026-06-17

Technologies: Oracle Enterprise Manager Base Platform. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle Enterprise Manager, a centralized management platform used to monitor and manage enterprise IT infrastructure. An unauthenticated attacker can exploit this flaw to take full control of the management platform, potentially impacting all connected systems and data. While the attack is launched over the network, it requires a legitimate user to perform a specific action, such as clicking a malicious link, to succeed.

Technical details

A vulnerability classified as Cross-Site Scripting (XSS) exists in the Metadata Plugin component of Oracle Enterprise Manager Base Platform (versions 13.5 and 24.1). The flaw (CWE-79) allows an unauthenticated remote attacker to send a malicious HTTP request that, when processed by a victim's browser, can lead to a full compromise of the platform. Although the attack vector is network-based and requires no privileges, it does require human interaction (UI:R) from a user other than the attacker. The vulnerability includes a scope change (S:C), meaning a successful exploit can impact security components beyond the immediate Oracle Enterprise Manager environment. Oracle has addressed this in the June 2026 security alerts.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References

Related threats