Executive brief
A vulnerability exists in the Security Framework of Oracle Enterprise Manager, a platform used by organizations to manage and monitor their Oracle software and hardware environments. An attacker with low-level access could trick a legitimate user into performing an action that allows the attacker to modify, insert, or delete certain data within the system. While this could lead to unauthorized changes to management data, it requires a victim to interact with a malicious link or request while logged in.
Technical details
This vulnerability is located in the Security Framework component of Oracle Enterprise Manager Base Platform version 24.1. It is classified as a low-complexity network attack that requires low-privileged credentials and user interaction (UI:R), suggesting a Cross-Site Request Forgery (CSRF) or similar UI-redirection flaw. A successful exploit allows an attacker to perform unauthorized update, insert, or delete operations on a subset of accessible data. The impact is limited to integrity, with no reported impact on confidentiality or availability. The issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Enterprise Manager Base Platform 24.1
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this CVE.
- 2026-07-21: disclosed