Junglewise Threat Intelligence

CVE-2026-46990: Oracle Enterprise Manager Base Platform vulnerability in Enterprise Config Management

CVE-2026-46990 · Severity: high · CVSS 7.3 · Published 2026-07-21

Technologies: Oracle Enterprise Manager Base Platform. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Enterprise Manager, a centralized management platform used to monitor and manage IT infrastructure. An unauthenticated attacker can exploit this flaw over the network to view, modify, or delete sensitive configuration data. This could lead to unauthorized changes in the management environment or a partial disruption of the monitoring service.

Technical details

A vulnerability in the Enterprise Config Management component of Oracle Enterprise Manager Base Platform allows an unauthenticated attacker with network access via HTTP to compromise the system. The flaw is categorized as easily exploitable (AC:L) and requires no user interaction. Successful exploitation enables an attacker to perform unauthorized read, update, insert, or delete operations on a subset of accessible data. Additionally, the vulnerability can be used to trigger a partial denial of service (DoS). The issue affects supported versions 13.5 and 24.1. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-07-21: advisory: Initial publication of CVE-2026-46990 by Oracle.

References

Related threats