Executive brief
A critical vulnerability has been identified in Oracle Enterprise Manager, a centralized platform used by organizations to manage and monitor their entire IT infrastructure. An unauthenticated attacker can exploit this flaw over the network to gain full control of the management platform. This could lead to a total loss of confidentiality, data integrity, and service availability across the managed environment.
Technical details
This vulnerability exists in the Oracle Management Service (OMS) component of the Oracle Enterprise Manager Base Platform. It is classified as an improper access control issue (CWE-284) that is easily exploitable via HTTP without requiring any user interaction or prior authentication. A successful exploit allows a remote attacker to achieve a complete takeover of the platform (Confidentiality, Integrity, and Availability impact). The vulnerability affects supported versions 13.5 and 24.1. Users are advised to refer to the Oracle June 2026 Security Alert for patching information.
Affected products
- Oracle Enterprise Manager Base Platform 13.5, 24.1
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle published the security alert.