Junglewise Threat Intelligence

CVE-2026-46999: Oracle Enterprise Manager Base Platform compromise in Discovery Framework

CVE-2026-46999 · Severity: high · CVSS 7 · Published 2026-07-21

Technologies: Oracle Enterprise Manager Base Platform. Vendors: Oracle.

Executive brief

A vulnerability exists in the Discovery Framework component of Oracle Enterprise Manager, a tool used by organizations to manage and monitor their IT infrastructure. An unauthenticated attacker could exploit this flaw over the network to gain unauthorized access to sensitive data or modify critical system information. This could lead to data loss, unauthorized changes to the management platform, or a partial disruption of the service.

Technical details

A vulnerability in the Oracle Enterprise Manager Base Platform (specifically the Discovery Framework component) allows an unauthenticated attacker with network access via HTTPS to compromise the system. The vulnerability is characterized by a high attack complexity, suggesting specific conditions or configurations must be met for successful exploitation. If exploited, an attacker can achieve unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to a subset of data. Additionally, the flaw can be used to cause a partial denial of service (DoS). Affected versions include 13.5 and 24.1. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-07-21: advisory: Initial publication of the CVE record and Oracle security alert.

References

Related threats