Junglewise Threat Intelligence

CVE-2026-46865: Oracle Enterprise Manager access control bypass in Extensibility Framework

CVE-2026-46865 · Severity: high · CVSS 8.2 · Published 2026-06-17

Technologies: Oracle Enterprise Manager Base Platform. Vendors: Oracle.

Executive brief

A vulnerability in the Oracle Enterprise Manager Base Platform's Extensibility Framework could allow a high-privileged user with access to the underlying server to take full control of the management platform. Oracle Enterprise Manager is used to monitor and manage large-scale IT environments; a compromise here could lead to unauthorized access or disruption across multiple connected systems and databases. This issue represents a significant risk to the confidentiality and integrity of the entire managed infrastructure.

Technical details

A vulnerability exists in the Extensibility Framework component of Oracle Enterprise Manager Base Platform (versions 13.5 and 24.1). The flaw is classified as an improper access control issue (CWE-284) that is easily exploitable by a high-privileged attacker who has local logon access to the infrastructure where the platform executes. Successful exploitation results in a 'scope change' (CVSS S:C), meaning the attacker can move beyond the management platform to impact other integrated products and systems. This can lead to a complete takeover of the Oracle Enterprise Manager Base Platform, affecting confidentiality, integrity, and availability. Oracle has addressed this in their June 2026 security alerts.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle published vendor advisory cspujun2026.html

References

Related threats