Junglewise Threat Intelligence

CVE-2026-46994: Oracle Enterprise Manager Base Platform takeover in Agent Next Gen

CVE-2026-46994 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle Enterprise Manager Base Platform. Vendors: Oracle.

Executive brief

A critical vulnerability has been identified in the Oracle Enterprise Manager Base Platform, a centralized tool used to manage and monitor large-scale IT environments. An unauthorized attacker could remotely take full control of the management platform over the network without needing a username or password. This could lead to a total loss of confidentiality, data integrity, and service availability across the managed infrastructure.

Technical details

This vulnerability exists in the Agent Next Gen component of Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. It is classified as easily exploitable, requiring no authentication or user interaction (CVSS 3.1 Base Score 9.8). An attacker with network access via HTTPS can exploit this flaw to achieve a complete compromise of the platform, impacting confidentiality, integrity, and availability. While the specific CWE is not detailed in the advisory, the impact is described as a full system takeover. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle in the July 2026 CPU
  • 2026-07-21: disclosed

References

Related threats