Junglewise Threat Intelligence

CVE-2026-46996: Oracle Enterprise Manager data manipulation in Metadata Plugin

CVE-2026-46996 · Severity: high · CVSS 7.1 · Published 2026-07-21

Technologies: Oracle Enterprise Manager Base Platform. Vendors: Oracle.

Executive brief

Oracle Enterprise Manager, a centralized platform for managing corporate IT infrastructure, contains a security vulnerability in its Metadata Plugin component. An attacker with basic user credentials can exploit this flaw over the network to modify, delete, or create critical system data. This could lead to significant operational disruption or the unauthorized alteration of sensitive business records.

Technical details

A vulnerability in the Metadata Plugin component of Oracle Enterprise Manager Base Platform (versions 13.5 and 24.1) allows for unauthorized data manipulation. The flaw is categorized as easily exploitable and requires low-privileged authentication to execute over HTTPS. Successful exploitation enables an attacker to gain unauthorized creation, deletion, or modification access to critical data or all accessible data within the platform, as well as limited read access to a subset of data. The vulnerability has a CVSS 3.1 base score of 7.1, primarily impacting data integrity and confidentiality. Users should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats