Junglewise Threat Intelligence

CVE-2026-46991: Oracle Enterprise Manager Base Platform data manipulation in Enterprise Config Management

CVE-2026-46991 · Severity: medium · CVSS 4.4 · Published 2026-07-21

Technologies: Oracle Enterprise Manager Base Platform. Vendors: Oracle.

Executive brief

A vulnerability exists in the Enterprise Config Management component of Oracle Enterprise Manager, a tool used by organizations to manage and monitor their IT infrastructure. An attacker who already has basic access to the server where this software is running can exploit this flaw to view, modify, or delete sensitive configuration data. While this requires an existing foothold on the system, it could allow a malicious insider or a compromised user account to interfere with IT operations and data integrity.

Technical details

This vulnerability affects the Enterprise Config Management component of the Oracle Enterprise Manager Base Platform. It is classified as a local exploit, meaning the attacker must have existing logon privileges to the infrastructure where the platform executes. The flaw allows a low-privileged user to perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of the platform's accessible data. The attack vector is local (AV:L) with low complexity (AC:L) and requires no user interaction (UI:N). The impact is limited to a partial loss of confidentiality and integrity (C:L/I:L) without affecting system availability.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.
  • 2026-07-21: disclosed

References

Related threats