Junglewise Threat Intelligence

CVE-2026-47005: Oracle Enterprise Manager Base Platform takeover in Self Update Framework

CVE-2026-47005 · Severity: high · CVSS 7.2 · Published 2026-07-21

Executive brief

Oracle Enterprise Manager, a centralized management platform for monitoring and managing Oracle IT environments, contains a vulnerability in its Self Update Framework. A high-privileged attacker can exploit this flaw over the network to gain full control of the management platform. This could lead to a total loss of confidentiality, integrity, and availability for the managed infrastructure.

Technical details

A vulnerability in the Self Update Framework component of Oracle Enterprise Manager Base Platform (versions 13.5 and 24.1) allows for a complete system compromise. The flaw is easily exploitable by a high-privileged attacker with network access via HTTPS. Successful exploitation results in a total takeover of the Oracle Enterprise Manager Base Platform, impacting confidentiality, integrity, and availability. The vulnerability is tracked as CVE-2026-47005 and was disclosed as part of the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-47005 by Oracle.

References

Related threats