Junglewise Threat Intelligence

CVE-2026-46989: Oracle Enterprise Manager Base Platform vulnerability in UI Framework

CVE-2026-46989 · Severity: critical · CVSS 9.1 · Published 2026-07-21

Technologies: Oracle Enterprise Manager Base Platform. Vendors: Oracle.

Executive brief

A vulnerability exists in the UI Framework of Oracle Enterprise Manager Base Platform, a tool used by organizations to manage and monitor their Oracle infrastructure. An attacker with low-level user credentials can exploit this flaw over the network to gain unauthorized access to sensitive data or modify system information. This could lead to a significant breach of managed data and cause partial service disruptions across the platform and connected systems.

Technical details

This vulnerability affects the UI Framework component of Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. It is classified as easily exploitable, requiring only low-privileged user authentication and network access via HTTPS. The exploit involves a scope change (S:C), meaning a successful attack on the Base Platform can impact other integrated products. Attackers can achieve unauthorized access to all accessible data, perform unauthorized data updates or deletions, and cause a partial denial of service. The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-07-21: disclosed: Initial advisory publication by Oracle.

References

Related threats