Junglewise Threat Intelligence

CVE-2026-46856: Oracle Enterprise Manager Base Platform vulnerability in Metadata Plugin

CVE-2026-46856 · Severity: critical · CVSS 9.6 · Published 2026-06-17

Technologies: Oracle Enterprise Manager Base Platform. Vendors: Oracle.

Executive brief

Oracle Enterprise Manager is a management platform used to monitor and manage Oracle software and hardware across an organization. A critical vulnerability in its Metadata Plugin component could allow an unauthenticated attacker to completely take over the system if a legitimate user interacts with a malicious link or site. This could lead to a total loss of confidentiality and control over the managed infrastructure, potentially impacting other connected systems.

Technical details

A vulnerability in the Metadata Plugin component of Oracle Enterprise Manager Base Platform (versions 13.5 and 24.1) is classified as a Cross-Site Scripting (XSS) or similar web-based injection flaw (CWE-79). The vulnerability is easily exploitable via HTTP by an unauthenticated remote attacker. While the attack requires human interaction (UI:R), the 'Scope Change' (S:C) designation indicates that a successful exploit allows the attacker to move beyond the privileges of the affected component to impact other products or the underlying platform. Successful exploitation can result in a complete takeover of the Oracle Enterprise Manager Base Platform, affecting confidentiality, integrity, and availability.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD publication date

References

Related threats