Executive brief
A vulnerability exists in the Oracle Enterprise Manager Base Platform, a tool used by organizations to manage and monitor their Oracle software and hardware environments. An unauthenticated attacker could exploit this flaw over the network to gain unauthorized access to sensitive information. While the attacker cannot modify data or shut down the system, the exposure of internal data could assist in further targeted attacks against the organization's infrastructure.
Technical details
This vulnerability affects the Agent Next Gen component of Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. It is classified as an information disclosure flaw that is easily exploitable by an unauthenticated attacker with network access via HTTPS. The vulnerability does not require user interaction and has a low attack complexity. Successful exploitation results in unauthorized read access to a subset of data managed by the platform, though it does not provide the ability to modify data or impact system availability. The issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Enterprise Manager Base Platform 13.5, 24.1
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this CVE.
- 2026-07-21: disclosed