Junglewise Threat Intelligence

CVE-2026-47002: Oracle Enterprise Manager Base Platform UI Framework vulnerability

CVE-2026-47002 · Severity: medium · CVSS 6.1 · Published 2026-07-21

Executive brief

A vulnerability exists in the user interface framework of Oracle Enterprise Manager, a tool used by organizations to manage and monitor their IT infrastructure. An attacker could exploit this flaw by tricking a legitimate user into performing an action, potentially allowing the attacker to view, modify, or delete sensitive management data. This could lead to unauthorized changes in the IT environment or the exposure of internal configuration details.

Technical details

A vulnerability in the UI Framework component of Oracle Enterprise Manager Base Platform (versions 13.5 and 24.1) allows an unauthenticated remote attacker to compromise the system. The flaw is categorized with a 'Scope Change' (S:C), suggesting it may be a Cross-Site Scripting (XSS) or similar UI-based injection vulnerability that allows an attacker to impact components beyond the immediate UI framework. Exploitation requires network access via HTTPS and successful social engineering to induce human interaction from a victim. If successful, the attacker can gain unauthorized read, update, or delete access to a subset of data accessible to the platform.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats