Junglewise Threat Intelligence

CVE-2026-47004: Oracle Enterprise Manager Base Platform takeover in Self Update Framework

CVE-2026-47004 · Severity: high · CVSS 8.8 · Published 2026-07-21

Executive brief

Oracle Enterprise Manager, a centralized platform for managing and monitoring enterprise IT environments, contains a vulnerability in its Self Update Framework. A low-privileged user with network access can exploit this flaw to take full control of the management platform. This could lead to a total loss of confidentiality, integrity, and availability for the managed infrastructure and its data.

Technical details

A vulnerability exists in the Self Update Framework component of Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. The flaw is categorized as easily exploitable and requires only low-privileged credentials to execute over the network via HTTPS. Successful exploitation allows an attacker to fully compromise the platform, leading to a complete takeover (High impact to Confidentiality, Integrity, and Availability). The vulnerability is tracked as CVE-2026-47004 with a CVSS 3.1 base score of 8.8. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats