Executive brief
A vulnerability in the Oracle Enterprise Manager Base Platform could allow a high-privileged user to take full control of the system. Oracle Enterprise Manager is a management platform used to monitor and manage Oracle software and hardware deployments. An exploit could lead to a complete compromise of the management platform, potentially impacting the availability and integrity of the managed environment.
Technical details
This vulnerability exists within the Extensibility Framework component of Oracle Enterprise Manager Base Platform (versions 13.5 and 24.1). It is classified as an improper privilege management issue (CWE-269) that is easily exploitable by an attacker with high-level administrative privileges. The attack vector is remote via HTTPS, requiring no user interaction. A successful exploit allows the attacker to achieve a complete takeover of the platform, impacting confidentiality, integrity, and availability. Oracle has addressed this in their June 2026 security alerts.
Affected products
- Oracle Enterprise Manager Base Platform 13.5, 24.1
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory