Junglewise Threat Intelligence

CVE-2026-46988: Oracle Enterprise Manager compromise in Connector Framework

CVE-2026-46988 · Severity: high · CVSS 7.2 · Published 2026-07-21

Technologies: Oracle Enterprise Manager Base Platform. Vendors: Oracle.

Executive brief

A vulnerability exists in the Connector Framework of Oracle Enterprise Manager, a centralized platform used by businesses to manage and monitor their entire IT infrastructure. A high-privileged attacker could exploit this flaw over the network to gain full control of the management platform. A successful compromise could lead to a total loss of confidentiality, integrity, and availability of the management system and the environments it oversees.

Technical details

This vulnerability is located in the Connector Framework component of the Oracle Enterprise Manager Base Platform. It is classified as easily exploitable, requiring network access via HTTPS. While the attack vector is remote, it requires high privileges (PR:H) to execute. A successful exploit allows for a complete takeover of the Oracle Enterprise Manager Base Platform, impacting confidentiality, integrity, and availability. The issue affects supported versions 13.5 and 24.1. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats