Junglewise Threat Intelligence

CVE-2026-46998: Oracle Enterprise Manager Base Platform takeover in Metadata Plugin

CVE-2026-46998 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Enterprise Manager Base Platform. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Enterprise Manager Base Platform, a tool used by organizations to manage and monitor their Oracle software and infrastructure. An unauthenticated attacker could exploit this flaw to gain full control over the management platform, potentially leading to the exposure of sensitive data or disruption of managed services. The attack requires a legitimate user to perform a specific action, such as clicking a malicious link, while logged into the system.

Technical details

A vulnerability in the Metadata Plugin component of Oracle Enterprise Manager Base Platform allows for a full system takeover. The flaw is exploitable by an unauthenticated attacker with network access via HTTPS. While the vulnerability is classified as easily exploitable, it requires user interaction (UI:R), suggesting a client-side attack vector such as Cross-Site Request Forgery (CSRF) or a similar injection that leverages a victim's session. Successful exploitation results in complete loss of confidentiality, integrity, and availability (C:H/I:H/A:H). Affected versions include 13.5 and 24.1. Users should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-07-21: advisory: Initial publication of CVE-2026-46998 by Oracle

References

Related threats