Executive brief
A critical vulnerability exists in Oracle Enterprise Manager, a centralized platform used by organizations to manage and monitor their entire IT infrastructure. A low-privileged user can exploit this flaw over the network to gain full control of the management platform. This could lead to a total service outage, unauthorized access to sensitive configuration data, and potential lateral movement to other connected systems managed by the platform.
Technical details
This vulnerability is located in the Metadata Plugin component of Oracle Enterprise Manager Base Platform. It is classified as an improper access control issue (CWE-284) that is easily exploitable via HTTPS. An attacker requires only low-level privileges and network access to trigger the flaw. The vulnerability is particularly severe because it involves a 'scope change' (CVSS S:C), meaning a successful compromise of the Base Platform can be used to impact other products and systems managed by the environment. The flaw results in a complete loss of confidentiality, integrity, and availability (takeover). Affected versions include 13.5 and 24.1.
Affected products
- Oracle Enterprise Manager Base Platform 13.5, 24.1
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published