Executive brief
Oracle Enterprise Manager, a centralized management platform for monitoring and managing Oracle IT environments, contains a vulnerability in its Self Update Framework. A high-privileged attacker can exploit this flaw over the network to gain full control of the management platform. This could lead to a total loss of confidentiality, integrity, and availability for the managed infrastructure.
Technical details
A vulnerability in the Self Update Framework component of Oracle Enterprise Manager Base Platform (versions 13.5 and 24.1) allows for a complete system compromise. The flaw is easily exploitable by a high-privileged attacker with network access via HTTPS. Successful exploitation results in a total takeover of the Oracle Enterprise Manager Base Platform, impacting confidentiality, integrity, and availability. The vulnerability is tracked as CVE-2026-47005 and was disclosed as part of the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle Enterprise Manager Base Platform 13.5, 24.1
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-47005 by Oracle.