Junglewise Threat Intelligence

CVE-2026-46995: Oracle Enterprise Manager Base Platform takeover in Metadata Plugin

CVE-2026-46995 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Enterprise Manager Base Platform. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Enterprise Manager, a centralized management platform used to monitor and manage enterprise IT infrastructure. An attacker with low-level access to the network can exploit this flaw to take full control of the management platform. This could lead to a total loss of data confidentiality and service availability across the managed environment.

Technical details

A vulnerability in the Metadata Plugin component of Oracle Enterprise Manager Base Platform (versions 13.5 and 24.1) allows for a complete system takeover. The flaw is easily exploitable by a low-privileged attacker with network access via HTTPS. Successful exploitation grants the attacker full control over the platform, impacting confidentiality, integrity, and availability (CVSS 8.8). While the specific CWE is not detailed in the advisory, the impact suggests a significant authorization or injection flaw within the plugin. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation steps.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD record published

References

Related threats