Junglewise Threat Intelligence

CVE-2026-46872: Oracle Enterprise Manager Base Platform vulnerability in Install component

CVE-2026-46872 · Severity: critical · CVSS 9 · Published 2026-06-17

Technologies: Oracle Enterprise Manager Base Platform. Vendors: Oracle.

Executive brief

A critical vulnerability exists in the installation component of Oracle Enterprise Manager, a tool used by organizations to manage their entire Oracle infrastructure. A high-privileged attacker can exploit this flaw over the network to gain unauthorized control over the platform, potentially leading to the theft or destruction of sensitive data. Additionally, an exploit can be used to crash the system, causing a total service outage and impacting other connected business products.

Technical details

This vulnerability affects the Install component of Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. It is classified as an 'easily exploitable' flaw that requires high privileges and network access via HTTPS. The exploit results in a 'scope change' (S:C), meaning a successful attack on this component can impact other parts of the environment. Attackers can achieve unauthorized creation, deletion, or modification of all accessible data, as well as read access to a subset of data. Furthermore, the vulnerability can be leveraged to cause a frequently repeatable crash or hang, resulting in a complete denial of service. Oracle has addressed this in their June 2026 security update.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References

Related threats