Executive brief
A security vulnerability exists in Oracle Enterprise Manager, a centralized management platform used to monitor and manage enterprise IT infrastructure. A high-privileged attacker could exploit this flaw to gain full control over the management platform. This could lead to a total loss of confidentiality, integrity, and availability of the systems managed by the platform.
Technical details
A vulnerability in the Self Update Framework component of Oracle Enterprise Manager Base Platform (versions 13.5 and 24.1) allows for a complete system compromise. The flaw is easily exploitable by a high-privileged attacker with network access via HTTPS. Successful exploitation results in a total takeover of the Oracle Enterprise Manager Base Platform, impacting confidentiality, integrity, and availability. The vulnerability is tracked as CVE-2026-47006 and was disclosed as part of the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle Enterprise Manager Base Platform 13.5, 24.1
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory