Junglewise Threat Intelligence

CVE-2026-46997: Oracle Enterprise Manager integrity vulnerability in Metadata Plugin

CVE-2026-46997 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle Enterprise Manager Base Platform. Vendors: Oracle.

Executive brief

A vulnerability exists in the Metadata Plugin component of Oracle Enterprise Manager, a centralized platform used for managing and monitoring enterprise IT environments. An attacker with low-level user credentials can exploit this flaw over the network to modify, create, or delete critical system data. This could lead to unauthorized configuration changes or the corruption of essential management data, potentially disrupting IT operations.

Technical details

An integrity-related vulnerability exists in the Metadata Plugin component of Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. The flaw is categorized as easily exploitable and requires low-privileged authentication to execute via HTTPS. Successful exploitation allows an attacker to perform unauthorized creation, deletion, or modification of data accessible to the platform. The vulnerability has a CVSS 3.1 base score of 6.5, specifically impacting data integrity while having no reported impact on confidentiality or availability. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats