Junglewise Threat Intelligence

CVE-2026-46864: Oracle Enterprise Manager Base Platform access control bypass in Agent Next Gen

CVE-2026-46864 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Oracle Enterprise Manager Base Platform. Vendors: Oracle.

Executive brief

A vulnerability in the Oracle Enterprise Manager Base Platform's Agent Next Gen component allows an attacker to take full control of the system. Oracle Enterprise Manager is used by organizations to manage and monitor their entire IT infrastructure, including databases and applications. If exploited, an attacker could gain unauthorized access to sensitive data, disrupt operations, or modify critical system configurations.

Technical details

This vulnerability exists in the Agent Next Gen component of Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. It is classified as an improper access control issue (CWE-284) that is easily exploitable by a low-privileged attacker with network access via SSH. Successful exploitation allows for a complete takeover of the Oracle Enterprise Manager Base Platform, impacting confidentiality, integrity, and availability. The attack does not require user interaction. Organizations are advised to refer to the Oracle June 2026 security alert for patching information.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD entry published

References

Related threats